CVE-2026-15149
5.3
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Summary
The WP Hotel Booking WordPress plugin before 2.3.3 does not ensure that room quantities and the resulting order total are non-negative when placing a booking, and relies on client-controlled cart data, allowing unauthenticated users to create confirmed reservations for free or at an arbitrarily reduced price.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | WP Hotel Booking | 0 < 2.3.3 | affected |
Weaknesses
- CWE-20 Improper Input Validation
- CWE-472 External Control of Assumed-Immutable Web Parameter
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.