Description
The MotoPress Hotel Booking WordPress plugin before 6.0.4 does not perform a capability check before returning a booking's full customer details in one of its AJAX actions, allowing any authenticated user with a low-privileged account (Subscriber and above) to read the personal data, including name, email, phone, and address, of any customer.
Published: 2026-07-30
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The MotoPress Hotel Booking WordPress plugin, in all versions prior to 6.0.4, fails to check user capabilities before executing an AJAX action that returns a booking’s full customer details. This flaw permits any authenticated user with a low‑privileged role, such as Subscriber, to read sensitive personal information—including name, email, phone number, and address—of any booking. The disclosed data can be used for phishing, identity theft, or other forms of exploitation, representing a clear confidentiality violation.

Affected Systems

The vulnerability affects installations of the MotoPress Hotel Booking plugin on WordPress sites running any version earlier than 6.0.4. All users logged into WordPress who have at least Subscriber status (or higher) can trigger the AJAX request and retrieve the protected customer data. The issue is specific to the Admin Calendar AJAX endpoint exposed by the plugin.

Risk and Exploitability

The CVSS score of 4.3 indicates a moderate severity. The EPSS score of less than 1% suggests that, while exploitation is possible, it is currently considered unlikely. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves an authenticated but low‑privileged user exploiting the exposed AJAX action; no elevated privileges or external network exposure are needed beyond access to the website’s administrative interface.

Generated by OpenCVE AI on August 3, 2026 at 11:16 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade MotoPress Hotel Booking to version 6.0.4 or later where the capability check is implemented.
  • Limit or remove Subscriber and higher role capabilities to prevent access to the vulnerable AJAX action, or re‑assign those roles to a group without permission to view booking details.
  • Block or restrict the specific AJAX endpoint (e.g., via web‑application firewall or .htaccess rules) for non‑administrator users to prevent unauthorized data retrieval.

Generated by OpenCVE AI on August 3, 2026 at 11:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 30 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 30 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Motopress Hotel Booking
Motopress Hotel Booking motopress Hotel Booking
Wordpress
Wordpress wordpress
Vendors & Products Motopress Hotel Booking
Motopress Hotel Booking motopress Hotel Booking
Wordpress
Wordpress wordpress

Thu, 30 Jul 2026 06:15:00 +0000

Type Values Removed Values Added
Description The MotoPress Hotel Booking WordPress plugin before 6.0.4 does not perform a capability check before returning a booking's full customer details in one of its AJAX actions, allowing any authenticated user with a low-privileged account (Subscriber and above) to read the personal data, including name, email, phone, and address, of any customer.
Title Hotel Booking Lite < 6.0.4 - Subscriber+ Sensitive Data Disclosure via Admin Calendar AJAX Action
References

Subscriptions

Motopress Hotel Booking Motopress Hotel Booking
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-07-30T18:25:44.439Z

Reserved: 2026-07-09T11:38:13.310Z

Link: CVE-2026-15235

cve-icon Vulnrichment

Updated: 2026-07-30T18:24:36.418Z

cve-icon NVD

Status : Deferred

Published: 2026-07-30T06:25:01.467

Modified: 2026-07-30T19:17:08.273

Link: CVE-2026-15235

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T11:30:03Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor