SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-15151

HIGH · CVSS 7.5 EPSS 0.23%

Source: NVD + CISA KEV + EPSS · Published 2026-08-02 · Last synced 2026-09-01

CyberRota Analysis

AI-Generated

The Five Star Restaurant Reservations WordPress plugin prior to version 2.7.23 is vulnerable due to a lack of capability checks on certain AJAX actions, enabling users with minimal booking-management roles to reset booking notification settings without proper authorization. This could lead to unauthorized changes in booking configurations, potentially disrupting restaurant operations and user experience. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate the risk of exploitation.

CVE
CVE-2026-15151
Severity
HIGH
CVSS
7.5
EPSS
0.23%
WordPress

Original NVD Description

The Five Star Restaurant Reservations WordPress plugin before 2.7.23 does not perform a capability check on one of its AJAX actions, allowing users with the lowest booking-management role (which by default cannot access the Five Star Restaurant Reservations WordPress plugin before 2.7.23's settings) to reset the site's configured booking notification rules.