Description
The MotoPress Appointment Booking WordPress plugin before 2.4.8 does not perform an authorization or ownership check when handling a user-supplied booking identifier on an unauthenticated endpoint, allowing unauthenticated attackers to permanently delete other users' reservations. This is an incomplete fix of CVE-2026-9180: the deletion remains reachable on sites using payment confirmation, confirmed through version 2.4.7.
Published: 2026-09-02
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The MotoPress Appointment Booking WordPress plugin before 2.4.8 accepts a booking identifier from an unauthenticated user on a public endpoint and performs no authorization or ownership check, allowing an attacker to permanently delete any reservation. The flaw results in integrity loss of reservation data and can disrupt service for users who have already paid or are waiting for confirmation. It does not provide the attacker with information about the site or other data, but the impact on the application state and user trust is significant.

Affected Systems

Any installation of MotoPress Appointment Booking for WordPress running a plugin version earlier than 2.4.8 is affected. The vulnerability remains present on sites using payment confirmation mechanisms up through version 2.4.7, regardless of additional configuration.

Risk and Exploitability

The EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog, but the lack of authentication on the deletion endpoint and the absolute need for no credentials suggest a high likelihood of exploitation in a production environment. The CVSS score is not provided, but the combination of unrestricted access and the irreversible effect of deleting reservations would lead evaluators to assign a severe rating. Attackers could simply send a crafted HTTP request to the deletion endpoint with a target booking ID from any device, requiring only network access to the WordPress site.

Generated by OpenCVE AI on September 2, 2026 at 07:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade MotoPress Appointment Booking to version 2.4.8 or later
  • If immediate patching is not feasible, block unauthenticated access to the deletion endpoint using a firewall rule or web application firewall
  • After deployment, monitor activity logs for any unexpected reservation deletions

Generated by OpenCVE AI on September 2, 2026 at 07:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 02 Sep 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Wed, 02 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Description The MotoPress Appointment Booking WordPress plugin before 2.4.8 does not perform an authorization or ownership check when handling a user-supplied booking identifier on an unauthenticated endpoint, allowing unauthenticated attackers to permanently delete other users' reservations. This is an incomplete fix of CVE-2026-9180: the deletion remains reachable on sites using payment confirmation, confirmed through version 2.4.7.
Title Appointment Booking Lite < 2.4.8 - Unauthenticated Arbitrary Reservation Deletion
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-02T06:00:16.728Z

Reserved: 2026-07-09T11:23:08.830Z

Link: CVE-2026-15232

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-02T06:17:16.340

Modified: 2026-09-02T06:17:16.340

Link: CVE-2026-15232

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T07:30:18Z

Weaknesses