PT-2026-92023 · WordPress · Motopress Hotel Booking

·

CVE-2026-90650

·

Published

2026-09-15

·

Updated

2026-09-16

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions MotoPress Hotel Booking versions prior to 6.2.5
Description Insufficient input sanitization and output escaping in the premium Stripe gateway integration allow unauthenticated attackers to perform Stored Cross-Site Scripting (XSS). The issue occurs because the webhook listener webhook-listener.php does not verify webhook signatures by default, as the Stripe signing secret is empty. This allows a forged webhook containing a malicious id variable to be written into the payment log. When an administrator views the payment, the script executes in their browser. To exploit this, an attacker needs a valid Stripe PaymentIntent ID to associate the forged webhook with a payment record.
Recommendations Update to version 6.2.5 or later. Configure a Stripe signing secret to enable cryptographic verification of webhooks. Restrict access to the webhook-listener.php handler if the premium Stripe gateway is not in use.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-90650

Affected Products

Motopress Hotel Booking