CVE-2026-15152
Received Received - Intake

WP Hotel Booking Plugin Payment Verification Bypass

Vulnerability report for CVE-2026-15152, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-06

Last updated on: 2026-08-06

Assigner: WPScan

Description

The WP Hotel Booking WordPress plugin before 2.3.2 does not verify that a payment notification corresponds to a payment made to the site's own merchant account, nor that the paid amount matches the booking total, allowing unauthenticated users to have their bookings marked as fully paid without any payment reaching the site owner.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-06
Last Modified
2026-08-06
Generated
2026-08-07
AI Q&A
2026-08-07
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
wp_hotel_booking wp_hotel_booking to 2.3.2 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the WP Hotel Booking WordPress plugin before version 2.3.2. It allows unauthenticated users to mark their bookings as fully paid without actually making a payment to the site owner. The plugin fails to verify if a payment notification matches a real payment to the site's merchant account or if the paid amount equals the booking total.

Impact Analysis

If you use this plugin, attackers could exploit it to trick the system into marking fake or unauthorized bookings as paid. This could lead to financial losses as bookings appear completed without actual payments. It may also cause confusion in booking management and revenue tracking.

Compliance Impact

This vulnerability could impact compliance by allowing unauthorized bookings to be processed, potentially leading to data exposure or financial discrepancies. GDPR requires accurate data handling and security, while HIPAA mandates secure financial transactions. Exploitation may violate these standards if personal or payment data is mishandled.

Mitigation Strategies

Update the WP Hotel Booking WordPress plugin to version 2.3.2 or later to address the vulnerability.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-15152. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart