Back to CVE List

CVE-2026-15235

Vulnerability Description

The MotoPress Hotel Booking WordPress plugin before 6.0.4 does not perform a capability check before returning a booking's full customer details in one of its AJAX actions, allowing any authenticated user with a low-privileged account (Subscriber and above) to read the personal data, including name, email, phone, and address, of any customer.

Vulnerability Details

Published Date
Last Modified
Source
NVD
Vendor
Unknown
Product
MotoPress Hotel Booking

External References

Discussion (0)

Add Comment

No comments yet. Be the first!