PatchSiren

WP Hotel Booking CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM WP Hotel Booking CVE published 2026-08-06

CVE-2026-15152

The WP Hotel Booking WordPress plugin before 2.3.2 does not verify that a payment notification corresponds to a payment made to the site's own merchant account, nor that the paid amount matches the booking total. This vulnerability allows unauthenticated users to have their bookings marked as fully paid without any payment reaching the site owner. The issue arises from a flawed payment notification verifi [truncated]