The Five Star Restaurant Reservations WordPress plugin before 2.7.23 does not perform a capability check on one of its AJAX actions, allowing users with the lowest booking-management role (which by default cannot access the Five Star Restaurant Reservations WordPress plugin before 2.7.23's settings) to reset the site's configured booking notification rules.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
The Five Star Restaurant Reservations WordPress plugin contains a privilege escalation vulnerability where AJAX actions lack proper capability checks. This allows users with minimal booking-management role permissions to reset critical site configuration—specifically notification rules—despite lacking administrative access. WordPress site owners using this plugin are at risk, as attackers with low-level accounts can manipulate booking notification settings, potentially disrupting business operations, enabling phishing attacks through altered notifications, or causing denial of service. The vulnerability affects versions before 2.7.23, making it a common attack vector for privilege escalation campaigns targeting WordPress installations.
While this specific CVE maps to CWE-284 (Improper Access Control) rather than discrete MITRE ATT&CK techniques, Casky's skill library would detect attack patterns associated with T1548 (Abuse Elevation Control Mechanism) and T1078 (Valid Accounts) through behavioral analysis. Practitioners using Casky would observe suspicious AJAX requests from low-privileged accounts targeting admin-level functions, anomalous configuration changes without corresponding administrative actions, and role-permission mismatches in audit logs. Extended reasoning across Casky's 754 security skills enables detection of the access control bypass pattern—identifying when unauthenticated or minimally-privileged actions trigger functions reserved for higher roles—allowing security teams to flag this exploitation technique before malicious configuration changes occur.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-15151. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation