CVE-2026-9822EPSS p26.7%

CVE-2026-9822CVE-2026-9822

Description

The WP Hotel Booking WordPress plugin before 2.3.1 does not enforce capability checks in several of its AJAX handlers, allowing authenticated users with Subscriber-level access to read other users' booking line items, enumerate active coupons, and read pricing data.

Scoring

EPSS0.34% probability of exploitation · percentile 26.7% · 2026-08-03T12:00:16Z
Last modified2026-06-19
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.