CVE-2026-15238 PUBLISHED

Hotel Booking Lite < 6.2.3 - Subscriber+ Customer Data Modification via IDOR

Assigner: WPScan
Reserved: 09.07.2026 Published: 10.08.2026 Updated: 10.08.2026

The MotoPress Hotel Booking WordPress plugin before 6.2.3 does not verify record ownership before updating customer records, allowing any authenticated user with a low-privileged account (Subscriber and above) to modify or overwrite the personal data of any customer by supplying an arbitrary identifier.

Product Status

Vendor Unknown
Product MotoPress Hotel Booking
Versions Default: unaffected
  • affected from 0 to 6.2.3 (excl.)

Credits

  • Haitam Lazaar finder
  • WPScan coordinator

References

Problem Types

  • CWE-639 Authorization Bypass Through User-Controlled Key CWE