Home

Description

The WP Hotel Booking WordPress plugin before 2.3.1 does not enforce capability checks in several of its AJAX handlers, allowing authenticated users with Subscriber-level access to read other users' booking line items, enumerate active coupons, and read pricing data.

PUBLISHED Reserved 2026-05-28 | Published 2026-06-19 | Updated 2026-06-19 | Assigner WPScan

Problem types

CWE-284 Improper Access Control

Product status

Default status
unaffected

Any version before 2.3.1
affected

Credits

Sanjorn Keeratirungsan finder

WPScan coordinator

References

wpscan.com/...rability/107fe41a-c5d9-4547-b413-bbd77cbab986/ exploit vdb-entry technical-description

cve.org (CVE-2026-9822)

nvd.nist.gov (CVE-2026-9822)

Download JSON