CVE-2026-15232 Details
Description
The MotoPress Appointment Booking WordPress plugin before 2.4.8 does not perform an authorization or ownership check when handling a user-supplied booking identifier on an unauthenticated endpoint, allowing unauthenticated attackers to permanently delete other users' reservations. This is an incomplete fix of CVE-2026-9180: the deletion remains reachable on sites using payment confirmation, confirmed through version 2.4.7.
A vulnerability exists in the MotoPress Appointment Booking WordPress plugin in versions prior to 2.4.8. The issue arises because the plugin does not implement proper authorization or ownership checks when processing user-supplied booking identifiers on an unauthenticated endpoint. This flaw allows unauthenticated attackers to permanently delete reservations made by other users. This vulnerability is an incomplete fix of CVE-2026-9180, as the deletion capability remains available on sites that use payment confirmation, a fact verified in version 2.4.7.
Users are advised to update the MotoPress Appointment Booking WordPress plugin to version 2.4.8 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 2, 2026CISA-ADP
Assessed Sep 2, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://wpscan.com/vulnerability/b0ffa74d-a03a-4eed-95c7-579360990d7f/ | [email protected] | AdvisoryExploitRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-639 | Authorization Bypass Through User-Controlled Key | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| MotoPress Appointment Booking | < 2.4.8 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 2, 2026 | CVE Modified | CISA-ADP |
| Sep 2, 2026 | New CVE Received | [email protected] |
Volerion