CVE-2026-15147: Five Star Restaurant Reservations < 2.7.23 - Unauthenticated Payment Bypass and Booking Confirmation via IDOR
The Five Star Restaurant Reservations WordPress plugin before 2.7.23 does not verify the authenticity of incoming payment notifications, failing to validate the payment recipient, amount, and status or to bind the notification to the intended booking, allowing unauthenticated attackers to mark arbitrary pending reservations as paid and confirmed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-15147?
CVE-2026-15147 has a medium severity rating of 5.3.
How do I fix CVE-2026-15147?
To fix CVE-2026-15147, update the Five Star Restaurant Reservations WordPress plugin to version 2.7.23 or higher.
What type of vulnerability is CVE-2026-15147?
CVE-2026-15147 is an unauthenticated payment bypass vulnerability due to improper verification in the Five Star Restaurant Reservations plugin.
What impact does CVE-2026-15147 have on my website?
CVE-2026-15147 allows unauthenticated attackers to manipulate payment notifications and mark bookings as confirmed.
Is CVE-2026-15147 specific to any version of the plugin?
Yes, CVE-2026-15147 affects versions of the Five Star Restaurant Reservations plugin prior to 2.7.23.