CVE-2026-15147

The Five Star Restaurant Reservations WordPress plugin before 2.7.23 does not verify the authenticity of incoming payment notifications, failing to validate the payment recipient, amount, and status or to bind the notification to the intended booking, allowing unauthenticated attackers to mark arbitrary pending reservations as paid and confirmed.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-06 22:16

Updated : 2026-08-26 16:31


NVD link : CVE-2026-15147

Mitre link : CVE-2026-15147

CVE.ORG link : CVE-2026-15147


JSON object : View

Products Affected

No product.

CWE
CWE-345

Insufficient Verification of Data Authenticity

CWE-639

Authorization Bypass Through User-Controlled Key