CVE-2026-15151

The Five Star Restaurant Reservations WordPress plugin before 2.7.23 does not perform a capability check on one of its AJAX actions, allowing users with the lowest booking-management role (which by default cannot access the Five Star Restaurant Reservations WordPress plugin before 2.7.23's settings) to reset the site's configured booking notification rules.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-02 06:16

Updated : 2026-08-26 16:31


NVD link : CVE-2026-15151

Mitre link : CVE-2026-15151

CVE.ORG link : CVE-2026-15151


JSON object : View

Products Affected

No product.

CWE
CWE-284

Improper Access Control