---
id: CVE-2026-15151
title: >-
  The Five Star Restaurant Reservations  WordPress plugin before 2.7.23 does not
  perform a capability check on one of its AJAX actions, allowing users with the
  lowest booking-management role (which by default cannot access the Five Star
  Re…
summary: >-
  The Five Star Restaurant Reservations  WordPress plugin before 2.7.23 does not
  perform a capability check on one of its AJAX actions, allowing users with the
  lowest booking-management role (which by default cannot access the Five Star
  Re…
severity: none
published: '2026-08-02'
updated: '2026-08-02'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-15151'
references:
  - url: 'https://wpscan.com/vulnerability/2c28e8b9-4293-4cf4-990d-09727275935b/'
    label: contact@wpscan.com
tags:
  - nvd
ingestedAt: '2026-08-02T13:18:28.971Z'
epss: 0.00232
epssPercentile: 0.14362
---

## Overview

The Five Star Restaurant Reservations  WordPress plugin before 2.7.23 does not perform a capability check on one of its AJAX actions, allowing users with the lowest booking-management role (which by default cannot access the Five Star Restaurant Reservations  WordPress plugin before 2.7.23's settings) to reset the site's configured booking notification rules.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
