SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-15153

MEDIUM · CVSS 6.8 EPSS 0.29%

Source: NVD + CISA KEV + EPSS · Published 2026-07-30 · Last synced 2026-08-29

CyberRota Analysis

AI-Generated

The WP Hotel Booking plugin for WordPress prior to version 2.3.2 is vulnerable to SQL injection due to improper sanitization and escaping of a search parameter in administrative listings. This flaw allows users with booking-management roles to execute malicious SQL queries, potentially compromising the database. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this risk.

CVE
CVE-2026-15153
Severity
MEDIUM
CVSS
6.8
EPSS
0.29%
WordPress

Original NVD Description

The WP Hotel Booking WordPress plugin before 2.3.2 does not sanitise and escape a search parameter on an administrative listing before using it in a SQL query, allowing users holding the WP Hotel Booking WordPress plugin before 2.3.2's booking-management roles to perform SQL injection attacks.