CVE-2026-15237 PUBLISHED

Hotel Booking Lite < 6.2.3 - Unauthenticated Payment Record Creation via Checkout Payments REST Endpoint

Assigner: WPScan
Reserved: 09.07.2026 Published: 10.08.2026 Updated: 10.08.2026

The MotoPress Hotel Booking WordPress plugin before 6.2.3 does not perform any authorization or ownership check on a REST endpoint that creates payment records, allowing unauthenticated users to create completed payment records against arbitrary bookings and falsely mark them as paid.

Product Status

Vendor Unknown
Product MotoPress Hotel Booking
Versions Default: unaffected
  • affected from 0 to 6.2.3 (excl.)

Credits

  • Haitam Lazaar finder
  • WPScan coordinator

References

Problem Types

  • CWE-862 Missing Authorization CWE