ZeroHour

CVE-2026-15149

CVSS 3.1
5.3 medium
EPSS
<1%p15
Published
()
Modified
Description

The WP Hotel Booking WordPress plugin before 2.3.3 does not ensure that room quantities and the resulting order total are non-negative when placing a booking, and relies on client-controlled cart data, allowing unauthenticated users to create confirmed reservations for free or at an arbitrarily reduced price.

Ecosystems
WordPress
Weakness
CWE-20, CWE-472
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

In the news

No ingested article mentions this CVE yet.