What the vulnerability does
01Description
The WP Hotel Booking WordPress plugin before 2.3.2 does not verify that a payment notification corresponds to a payment made to the site's own merchant account, nor that the paid amount matches the booking total, allowing unauthenticated users to have their bookings marked as fully paid without any payment reaching the site owner.
Explanation of Vulnerability in Simple Terms
02Summary
WP Hotel Booking versions before 2.3.2 contain an integrity vulnerability allowing network-based modification of data without authentication. An attacker can alter information on the site by sending specially crafted requests. No user interaction or elevated privileges are required. Update to version 2.3.2 or later to resolve this issue.
What an attacker can do
03Attacker Capabilities
Modify data on the site via network requests without needing to log in.
Potential impact on your site
04Site Impact
Attackers can alter booking data, settings, or other site content without authorization.
Conditions required to exploit
05Prerequisites
Network access to the site; no authentication or user interaction required.
Key dates
06Disclosure timeline
August 6, 2026
CVE published