CVE-2026-15147
Five Star Restaurant Reservations < 2.7.23 - Unauthenticated Payment Bypass and Booking Confirmation via IDOR
CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th
The Five Star Restaurant Reservations WordPress plugin before 2.7.23 does not verify the authenticity of incoming payment notifications, failing to validate the payment recipient, amount, and status or to bind the notification to the intended booking, allowing unauthenticated attackers to mark arbitrary pending reservations as paid and confirmed.
| Vendor | unknown |
| Product | five star restaurant reservations |
| Published | Aug 6, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown five star restaurant reservations
Be the first to know when new medium vulnerabilities affecting unknown five star restaurant reservations are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
Unknown / Five Star Restaurant Reservations
0 < 2.7.23
References
Credits
Muni Nitish Kumar Yaddala WPScan