CVE-2026-15153

WP Hotel Booking < 2.3.2 - Hotel Manager+ SQL Injection via Booking List Search

The WP Hotel Booking WordPress plugin before 2.3.2 does not sanitise and escape a search parameter on an administrative listing before using it in a SQL query, allowing users holding the WP Hotel Booking WordPress plugin before 2.3.2's booking-management roles to perform SQL injection attacks.


We have discovered 1,804 live websites that are affected by CVE-2026-15153.

Run a Free Instant Scan




Affected Software

Product  Wp Hotel Booking
Category Wordpress Plugins
Vulnerable Domains1,804 live websites (99% of Wp Hotel Booking install base)
Vulnerable Versions
  • from 0 through 2.3.2
Vulnerable Versions Count47 versions ( 98% of all versions)


Common Weakness Enumeration

CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')



Details

  • Published - Jul 30, 2026
  • Updated - Jul 30, 2026

Credits

  • Mokksh Parekh (finder)
  • WPScan (coordinator)

Website Distribution by Country

Number of websites using CVE-2026-15153
United States348 websites



Italy247 websites
Germany158 websites
Greece95 websites
France94 websites
India77 websites
Turkey54 websites
Romania51 websites
Spain50 websites
GB50 websites

Website Distribution by TLD

Number of websites using CVE-2026-15153
.com933 websites
.it166 websites
.de49 websites
.pl30 websites
.co.uk25 websites
.com.br25 websites
.ru22 websites
.net22 websites
.fr21 websites
.com.au19 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-15153

Top websites that are affected by CVE-2026-15153. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***************.org Italy***,***
******.***.ca Canada*,***,***
*************.com United States*,***,***
***************.net Germany*,***,***
**************.de Germany*,***,***
*****************.com United States*,***,***
**********.com United States*,***,***
**************.nl Netherlands*,***,***
**********************.xn--90ais Belarus*,***,***
**********.fr France*,***,***
See full domain list

FAQ

CVE-2026-15153 is Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in Wp Hotel Booking
A total of 1,804 websites have been identified as vulnerable to CVE-2026-15153, based on global website indexing conducted by WebTechSurvey.
The Wp Hotel Booking is affected by the CVE-2026-15153 vulnerability.
Wp Hotel Booking versions up to 2.3.2 are vulnerable to CVE-2026-15153.
CVE-2026-15153 is resolved in version 2.3.2 of Wp Hotel Booking.