What is CVE-2026-15464?
CVE-2026-15464 is a Stored Cross-Site Scripting vulnerability in the WP Hotel Booking plugin for WordPress. It exists due to insufficient input sanitization in the 'widget_search' Shortcode attribute, allowing authenticated Contributor-level users to inject malicious scripts. This affects all versions up to 2.3.2, and updating is strongly recommended.
Azərbaycanca: CVE-2026-15464 WordPress üçün WP Hotel Booking plaginində aşkar edilmiş Stored XSS zəifliyidir. 'widget_search' Shortcode atributunda kifayət qədər input sanitization olmaması səbəbindən Contributor səviyyəli istifadəçilər tərəfindən istismar edilə bilər. Plaginin 2.3.2 və aşağı versiyalarını istifadə edən saytlar təhlükə altındadır, təcili yenilənmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which user role can exploit the CVE-2026-15464 vulnerability in the WP Hotel Booking plugin?
This vulnerability can be exploited by authenticated Contributor-level users.
What is the root cause of the CVE-2026-15464 security flaw?
The vulnerability exists due to insufficient input sanitization in the 'widget_search' Shortcode attribute.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.