CVE-2026-9822EPSS p25.3%

CVE-2026-9822CVE-2026-9822

Description

The WP Hotel Booking WordPress plugin before 2.3.1 does not enforce capability checks in several of its AJAX handlers, allowing authenticated users with Subscriber-level access to read other users' booking line items, enumerate active coupons, and read pricing data.

Scoring

EPSS0.34% probability of exploitation · percentile 25.3% · 2026-10-06T12:00:23Z
Last modified2026-06-19
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.