Medium severity5.3NVD Advisory· Published Aug 6, 2026
CVE-2026-15152
CVE-2026-15152
Description
The WP Hotel Booking WordPress plugin before 2.3.2 does not verify that a payment notification corresponds to a payment made to the site's own merchant account, nor that the paid amount matches the booking total, allowing unauthenticated users to have their bookings marked as fully paid without any payment reaching the site owner.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <2.3.2
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.