๐Ÿ” CVE Alert

CVE-2026-15237

UNKNOWN 0.0

Hotel Booking Lite < 6.2.3 - Unauthenticated Payment Record Creation via Checkout Payments REST Endpoint

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The MotoPress Hotel Booking WordPress plugin before 6.2.3 does not perform any authorization or ownership check on a REST endpoint that creates payment records, allowing unauthenticated users to create completed payment records against arbitrary bookings and falsely mark them as paid.

Vendor unknown
Product motopress hotel booking
Published Aug 10, 2026
Stay Ahead of the Next One

Get instant alerts for unknown motopress hotel booking

Be the first to know when new unknown vulnerabilities affecting unknown motopress hotel booking are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / MotoPress Hotel Booking
0 < 6.2.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/b312a323-808c-497f-b67e-3b0acfcb8932/

Credits

Haitam Lazaar WPScan