PT-2026-92023 · WordPress · Motopress Hotel Booking
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
MotoPress Hotel Booking versions prior to 6.2.5
Description
Insufficient input sanitization and output escaping in the premium Stripe gateway integration allow unauthenticated attackers to perform Stored Cross-Site Scripting (XSS). The issue occurs because the webhook listener
webhook-listener.php does not verify webhook signatures by default, as the Stripe signing secret is empty. This allows a forged webhook containing a malicious id variable to be written into the payment log. When an administrator views the payment, the script executes in their browser. To exploit this, an attacker needs a valid Stripe PaymentIntent ID to associate the forged webhook with a payment record.Recommendations
Update to version 6.2.5 or later.
Configure a Stripe signing secret to enable cryptographic verification of webhooks.
Restrict access to the
webhook-listener.php handler if the premium Stripe gateway is not in use.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Motopress Hotel Booking