CVE-2026-15151 UNKNOWN

CVE-2026-15151

Published: 2026-08-02

Description

The Five Star Restaurant Reservations WordPress plugin before 2.7.23 does not perform a capability check on one of its AJAX actions, allowing users with the lowest booking-management role (which by default cannot access the Five Star Restaurant Reservations WordPress plugin before 2.7.23's settings) to reset the site's configured booking notification rules.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…