PT-2026-69349 · WordPress · Motopress Hotel Booking
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
MotoPress Hotel Booking WordPress plugin versions prior to 6.2.3
Description
An issue exists where the software fails to perform authorization or ownership checks on a REST endpoint used to create payment records. This allows unauthenticated users to create completed payment records for arbitrary bookings, falsely marking them as paid.
Recommendations
Update the MotoPress Hotel Booking WordPress plugin to version 6.2.3 or later.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Motopress Hotel Booking