AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-15237

MEDIUM · CVSS 5.3 EPSS 0.22%

Source: NVD + CISA KEV + EPSS · Published 2026-08-10 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The MotoPress Hotel Booking plugin for WordPress versions prior to 6.2.3 is vulnerable due to a lack of authorization checks on a REST endpoint, enabling unauthenticated users to create fraudulent payment records for any booking. This could lead to financial discrepancies and unauthorized access to booking management. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential exploitation.

CVE
CVE-2026-15237
Severity
MEDIUM
CVSS
5.3
EPSS
0.22%
WordPress

Original NVD Description

The MotoPress Hotel Booking WordPress plugin before 6.2.3 does not perform any authorization or ownership check on a REST endpoint that creates payment records, allowing unauthenticated users to create completed payment records against arbitrary bookings and falsely mark them as paid.