GHSA-vqh4-pqm8-4r46MediumCVSS 5.3

The MotoPress Hotel Booking WordPress plugin before 6.2.3 does not perform any authorization or...

Published
August 10, 2026
Last Modified
August 11, 2026

🔗 CVE IDs covered (1)

📋 Description

The MotoPress Hotel Booking WordPress plugin before 6.2.3 does not perform any authorization or ownership check on a REST endpoint that creates payment records, allowing unauthenticated users to create completed payment records against arbitrary bookings and falsely mark them as paid.

🔗 References (3)