CVE-2026-15152: WP Hotel Booking < 2.3.2 - Unauthenticated PayPal Payment Bypass
The WP Hotel Booking WordPress plugin before 2.3.2 does not verify that a payment notification corresponds to a payment made to the site's own merchant account, nor that the paid amount matches the booking total, allowing unauthenticated users to have their bookings marked as fully paid without any payment reaching the site owner.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-15152?
The severity of CVE-2026-15152 is rated as medium with a score of 5.3.
How do I fix CVE-2026-15152?
To fix CVE-2026-15152, update the WP Hotel Booking plugin to version 2.3.2 or later.
What does CVE-2026-15152 affect?
CVE-2026-15152 affects the WP Hotel Booking WordPress plugin versions prior to 2.3.2.
What is the risk of CVE-2026-15152?
The risk of CVE-2026-15152 is categorized with a risk level of 27, indicating potential exploitation.
What issue does CVE-2026-15152 address?
CVE-2026-15152 addresses the lack of verification for payment notifications in the WP Hotel Booking plugin, allowing unauthorized bookings to be marked as paid.