CyberRota Analysis
AI-GeneratedThe MotoPress Hotel Booking WordPress plugin prior to version 6.2.3 is vulnerable due to inadequate verification of record ownership, enabling authenticated users with low-privileged accounts (Subscriber and above) to alter or overwrite customer personal data by using arbitrary identifiers. This flaw poses a significant risk to data integrity and privacy, making it essential for WordPress site administrators using this plugin to prioritize updates to mitigate potential data breaches.
Original NVD Description
The MotoPress Hotel Booking WordPress plugin before 6.2.3 does not verify record ownership before updating customer records, allowing any authenticated user with a low-privileged account (Subscriber and above) to modify or overwrite the personal data of any customer by supplying an arbitrary identifier.