The WP Hotel Booking WordPress plugin before 2.3.2 does not sanitise and escape a search parameter on an administrative listing before using it in a SQL query, allowing users holding the WP Hotel Booking WordPress plugin before 2.3.2's booking-management roles to perform SQL injection attacks.
We have discovered 1,804 live websites that are affected by CVE-2026-15153.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 1,804 live websites (99% of Wp Hotel Booking install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 47 versions ( 98% of all versions) |
| 348 websites | |
| 247 websites | |
| 158 websites | |
| 95 websites | |
| 94 websites | |
| 77 websites | |
| 54 websites | |
| 51 websites | |
| 50 websites | |
| 50 websites |
| .com | 933 websites |
| .it | 166 websites |
| .de | 49 websites |
| .pl | 30 websites |
| .co.uk | 25 websites |
| .com.br | 25 websites |
| .ru | 22 websites |
| .net | 22 websites |
| .fr | 21 websites |
| .com.au | 19 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ***************.org | ***,*** | ||
| ******.***.ca | *,***,*** | ||
| *************.com | *,***,*** | ||
| ***************.net | *,***,*** | ||
| **************.de | *,***,*** | ||
| *****************.com | *,***,*** | ||
| **********.com | *,***,*** | ||
| **************.nl | *,***,*** | ||
| **********************.xn--90ais | *,***,*** | ||
| **********.fr | *,***,*** |
FAQ