๐Ÿ” CVE Alert

CVE-2026-15238

UNKNOWN 0.0

Hotel Booking Lite < 6.2.3 - Subscriber+ Customer Data Modification via IDOR

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The MotoPress Hotel Booking WordPress plugin before 6.2.3 does not verify record ownership before updating customer records, allowing any authenticated user with a low-privileged account (Subscriber and above) to modify or overwrite the personal data of any customer by supplying an arbitrary identifier.

Vendor unknown
Product motopress hotel booking
Published Aug 10, 2026
Stay Ahead of the Next One

Get instant alerts for unknown motopress hotel booking

Be the first to know when new unknown vulnerabilities affecting unknown motopress hotel booking are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / MotoPress Hotel Booking
0 < 6.2.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/7283a28a-7241-4b9e-8fc5-5b427191c80e/

Credits

Haitam Lazaar WPScan