CVE-2026-15153
WP Hotel Booking < 2.3.2 - Hotel Manager+ SQL Injection via Booking List Search
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The WP Hotel Booking WordPress plugin before 2.3.2 does not sanitise and escape a search parameter on an administrative listing before using it in a SQL query, allowing users holding the WP Hotel Booking WordPress plugin before 2.3.2's booking-management roles to perform SQL injection attacks.
| Vendor | unknown |
| Product | wp hotel booking |
| Published | Jul 30, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown wp hotel booking
Be the first to know when new unknown vulnerabilities affecting unknown wp hotel booking are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / WP Hotel Booking
0 < 2.3.2
References
Credits
Mokksh Parekh WPScan