Home/Security Research

CVE-2026-15151

LOW — CVSS 3.8

Booking Manager+ Missing Authorization in WordPress Five Star Restaurant Reservations Plugin

PluginFive Star Restaurant Reservations (restaurant-reservations)
Affected< 2.7.23
Fixed in2.7.23
VulnerabilityMissing Authorization / Improper Access Control (CWE-284)
CVSS Score3.8 Low (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L)
Required RoleBooking Manager or higher
Discovered byMd Minaruzzaman Shovon
ReportedJuly 2026
DisclosedJuly 2026

Summary

A Missing Authorization vulnerability exists in the WordPress Five Star Restaurant Reservations plugin in versions prior to 2.7.23. The plugin does not perform a capability check on one of its AJAX actions.

Users with the lowest booking-management role, who by default cannot access the plugin's settings, can reset the site's configured booking notification rules.

Technical Details

The plugin ships a Booking Manager role intended only for handling reservations (read + manage_bookings, without manage_options). The rtb_reset_notifications AJAX handler, which restores the notification configuration to its defaults, verified a nonce but never checked that the caller was allowed to manage plugin settings.

Because the nonce is exposed on the bookings page that Booking Managers can already access, a user with that role can obtain it and invoke the settings-level action directly.

Attack vector: Authenticated (Booking Manager+) POST request to wp-admin/admin-ajax.php with action=rtb_reset_notifications and a valid nonce from the bookings page.

Impact

  • Privilege boundary bypass between booking staff and site administrators
  • Reset of the restaurant's custom booking notification rules without authorization
  • Disruption of automated notification workflows for guests and staff

Remediation

Update Five Star Restaurant Reservations to version 2.7.23 or later, which adds the missing capability check to the notification reset action.

References & Disclosure Timeline

Timeline:
• July 2026 — Vulnerability discovered & reported to vendor via WPScan
• July 20, 2026 — WPScan advisory published; fix released in 2.7.23
• August 2, 2026 — CVE-2026-15151 published