CVE-2026-15151
Received Received - Intake

Unauthorized Settings Reset in Five Star Restaurant Reservations WordPress Plugin

Vulnerability report for CVE-2026-15151, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-02

Last updated on: 2026-08-02

Assigner: WPScan

Description

The Five Star Restaurant Reservations WordPress plugin before 2.7.23 does not perform a capability check on one of its AJAX actions, allowing users with the lowest booking-management role (which by default cannot access the Five Star Restaurant Reservations WordPress plugin before 2.7.23's settings) to reset the site's configured booking notification rules.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-02
Last Modified
2026-08-02
Generated
2026-08-02
AI Q&A
2026-08-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
five_star_restaurant_reservations five_star_restaurant_reservations to 2.7.23 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability exists in the Five Star Restaurant Reservations WordPress plugin before version 2.7.23. It allows users with the lowest booking-management role to reset the site's booking notification rules without proper permission checks.

Detection Guidance

Check if the Five Star Restaurant Reservations WordPress plugin version is below 2.7.23. Log in to your WordPress admin panel and navigate to Plugins to verify the installed version. If you have command-line access, you can use WP-CLI with the command: wp plugin list | grep five_star_restaurant_reservations.

Impact Analysis

An attacker with minimal access could alter notification settings, potentially disrupting booking management and causing confusion or missed reservations.

Compliance Impact

This vulnerability does not directly affect compliance with GDPR, HIPAA, or other common standards and regulations. The issue involves unauthorized access to booking notification rules in a WordPress plugin, which is unrelated to data protection or privacy requirements.

Mitigation Strategies

Update the Five Star Restaurant Reservations plugin to version 2.7.23 or later immediately. If updating is not possible, consider temporarily disabling the plugin until an update can be applied. Review user roles and permissions to ensure only authorized users have access to booking management features.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-15151. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart