GHSA-2r7r-792g-6mpgMediumCVSS 5.4

The MotoPress Hotel Booking WordPress plugin before 6.2.3 does not verify record ownership before...

Published
August 10, 2026
Last Modified
August 11, 2026

🔗 CVE IDs covered (1)

📋 Description

The MotoPress Hotel Booking WordPress plugin before 6.2.3 does not verify record ownership before updating customer records, allowing any authenticated user with a low-privileged account (Subscriber and above) to modify or overwrite the personal data of any customer by supplying an arbitrary identifier.

🔗 References (3)