PT-2026-42738 · WordPress · Motopress Hotel Booking
Published
2026-05-22
·
Updated
2026-05-22
·
CVE-2026-8684
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
MotoPress Hotel Booking versions prior to 6.0.2
Description
The MotoPress Hotel Booking plugin for WordPress contains an authorization bypass flaw resulting from improper verification of user permissions. Unauthenticated attackers can overwrite or delete internal notes by providing an arbitrary booking ID. This is possible because the required nonce is exposed in the HTML source of all public pages via
wp localize script in the MPHB. data.nonces variable, allowing any visitor to perform the action without an account. The affected variable is mphb booking internal notes.Recommendations
Update to version 6.0.2 or later.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Motopress Hotel Booking