Impact
The MotoPress Hotel Booking plugin for WordPress contains a stored cross‑site scripting flaw that allows attackers to inject arbitrary JavaScript into the payment log through the Stripe webhook event object 'id'. The flaw arises from insufficient sanitization of the 'id' field before it is written to the logs and subsequently echoed to administrators, enabling the execution of malicious scripts in the context of any user who views the affected page. An attacker can thus steal credentials, deface content, or perform other browser‑side attacks without needing site authentication.
Affected Systems
All releases of the MotoPress Hotel Booking plugin up to and including version 6.2.4 are affected. The issue resides in the premium Stripe webhook listener component; the lite plugin does not contain the vulnerable code. The flaw is triggered when a forged Stripe webhook with a manipulated 'id' field is processed and logged.
Risk and Exploitability
The CVSS base score of 7.2 reflects the high impact of an XSS vulnerability coupled with the lack of authentication for exploitation. Exploitation is possible because the webhook listener only verifies the signature when an optional Stripe signing secret has been configured, which is empty by default. An attacker only needs to know a valid Stripe PaymentIntent ID to route a forged webhook to an existing payment record. While the vulnerability is not listed in the CISA KEV catalog and the EPSS score is 0.236%, the requirement of a known PaymentIntent ID does not substantially lower the threat level for environments using Stripe. The immediacy of the attack vector—sending a crafted webhook to the plugin’s endpoint—makes the use of this exploit straightforward for determined adversaries.
OpenCVE Enrichment