CVE-2026-15235
Vulnerability Description
The MotoPress Hotel Booking WordPress plugin before 6.0.4 does not perform a capability check before returning a booking's full customer details in one of its AJAX actions, allowing any authenticated user with a low-privileged account (Subscriber and above) to read the personal data, including name, email, phone, and address, of any customer.
Vulnerability Details
Published Date
Last Modified
Source
NVD
Vendor
Unknown
Product
MotoPress Hotel Booking
Discussion (0)
Add Comment
No comments yet. Be the first!