Vulnerability Description
The MotoPress Hotel Booking WordPress plugin before 6.2.3 does not verify record ownership before updating customer records, allowing any authenticated user with a low-privileged account (Subscriber and above) to modify or overwrite the personal data of any customer by supplying an arbitrary identifier.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
FAQ
What is CVE-2026-15238?
CVE-2026-15238 is a vulnerability with a CVSS score of 5.4 (MEDIUM). The MotoPress Hotel Booking WordPress plugin before 6.2.3 does not verify record ownership before updating customer records, allowing any authenticated user with a low-privileged account (Subscriber a...
How severe is CVE-2026-15238?
CVE-2026-15238 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-15238?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.