CVE-2026-15147 MEDIUM

CVE-2026-15147: Five Star Restaurant Reservations < 2.7.23 - Unauthenticated Payment Bypass and Booking Confirmation via IDOR

Vendor Unknown
Product Five Star Restaurant Reservations
Published August 6, 2026
Last update August 6, 2026

CVSS base score

5.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality None
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

What the vulnerability does

01Description

The Five Star Restaurant Reservations WordPress plugin before 2.7.23 does not verify the authenticity of incoming payment notifications, failing to validate the payment recipient, amount, and status or to bind the notification to the intended booking, allowing unauthenticated attackers to mark arbitrary pending reservations as paid and confirmed.

Explanation of Vulnerability in Simple Terms

02Summary

Five Star Restaurant Reservations versions before 2.7.23 contain an integrity vulnerability allowing network-based modification of data without authentication. An attacker can alter reservation records or other application data over the network. No user interaction is required. Update to version 2.7.23 or later to resolve this issue.

What an attacker can do

03Attacker Capabilities

Modify reservation data or other application information without logging in.

Potential impact on your site

04Site Impact

Attackers can alter restaurant reservations, customer details, or other critical booking data without credentials.

Conditions required to exploit

05Prerequisites

Network access to the application; no authentication or user interaction required.

Key dates

06Disclosure timeline

August 6, 2026 CVE published