CVE-2026-15153

The WP Hotel Booking WordPress plugin before 2.3.2 does not sanitise and escape a search parameter on an administrative listing before using it in a SQL query, allowing users holding the WP Hotel Booking WordPress plugin before 2.3.2's booking-management roles to perform SQL injection attacks.
Configurations

No configuration.

History

No history.

Information

Published : 2026-07-30 06:25

Updated : 2026-07-30 19:17


NVD link : CVE-2026-15153

Mitre link : CVE-2026-15153

CVE.ORG link : CVE-2026-15153


JSON object : View

Products Affected

No product.

CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')