๐Ÿ” CVE Alert

CVE-2026-15235

UNKNOWN 0.0

Hotel Booking Lite < 6.0.4 - Subscriber+ Sensitive Data Disclosure via Admin Calendar AJAX Action

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The MotoPress Hotel Booking WordPress plugin before 6.0.4 does not perform a capability check before returning a booking's full customer details in one of its AJAX actions, allowing any authenticated user with a low-privileged account (Subscriber and above) to read the personal data, including name, email, phone, and address, of any customer.

Vendor unknown
Product motopress hotel booking
Published Jul 30, 2026
Stay Ahead of the Next One

Get instant alerts for unknown motopress hotel booking

Be the first to know when new unknown vulnerabilities affecting unknown motopress hotel booking are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / MotoPress Hotel Booking
0 < 6.0.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/c441d996-e21f-4a16-8dcc-0b0ed61aec76/

Credits

Sanjorn Keeratirungsan WPScan