AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-15238

MEDIUM · CVSS 5.4 EPSS 0.17%

Source: NVD + CISA KEV + EPSS · Published 2026-08-10 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The MotoPress Hotel Booking WordPress plugin prior to version 6.2.3 is vulnerable due to inadequate verification of record ownership, enabling authenticated users with low-privileged accounts (Subscriber and above) to alter or overwrite customer personal data by using arbitrary identifiers. This flaw poses a significant risk to data integrity and privacy, making it essential for WordPress site administrators using this plugin to prioritize updates to mitigate potential data breaches.

CVE
CVE-2026-15238
Severity
MEDIUM
CVSS
5.4
EPSS
0.17%
WordPress

Original NVD Description

The MotoPress Hotel Booking WordPress plugin before 6.2.3 does not verify record ownership before updating customer records, allowing any authenticated user with a low-privileged account (Subscriber and above) to modify or overwrite the personal data of any customer by supplying an arbitrary identifier.