What is CVE-2026-15238?
This vulnerability exists in the MotoPress Hotel Booking WordPress plugin before version 6.2.3. It allows any authenticated low-privileged user (such as Subscriber) to modify or overwrite customers' personal data by not verifying record ownership. Immediately update the plugin to the latest version to mitigate the risk.
Azərbaycanca: Bu boşluq MotoPress Hotel Booking WordPress plugin-inin 6.2.3-dən əvvəlki versiyalarında aşkarlanıb. O, autentifikasiya olunmuş istənilən aşağı səviyyəli istifadəçiyə (məsələn, Abunəçi) müştəri qeydlərinin sahibliyini yoxlamadan onların şəxsi məlumatlarını dəyişməyə imkan verir. Plugin-i dərhal ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which user roles are affected by the CVE-2026-15238 vulnerability in the MotoPress Hotel Booking plugin?
This vulnerability allows any authenticated low-privileged user, such as a Subscriber, to modify customers' personal data.
How can I protect my site from CVE-2026-15238?
You should immediately update the MotoPress Hotel Booking plugin to the latest version (6.2.3 or higher).
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.