What is CVE-2026-15237?
This is a critical vulnerability in the MotoPress Hotel Booking WordPress plugin versions prior to 6.2.3. A lack of authorization checks on a REST endpoint allows unauthenticated users to create fake completed payment records for arbitrary bookings, falsely marking them as paid. Immediate update to version 6.2.3 or higher is strongly recommended.
Azərbaycanca: Bu, MotoPress Hotel Booking WordPress plugin-in 6.2.3-dən əvvəlki versiyalarında tapılan kritik zəiflikdir. REST endpoint-də avtorizasiya olmaması səbəbindən autentifikasiya olunmamış istifadəçilər istənilən rezervasiya üçün saxta ödəniş qeydləri yaradıb, bronları yanlış olaraq ödənilmiş kimi göstərə bilərlər. Plugin-i dərhal 6.2.3 versiyasına və ya daha yuxarı yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
What can an attacker do by exploiting CVE-2026-15237?
An unauthenticated user exploiting this vulnerability can create fake completed payment records for arbitrary bookings via the REST endpoint, falsely marking them as paid.
How can I fix the CVE-2026-15237 vulnerability?
It is strongly recommended to immediately update the MotoPress Hotel Booking plugin to version 6.2.3 or higher.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.