SecAlerts
m

motopress

Security Risk Profile

40
/100
medium

Security Risk Score

Comprehensive risk assessment based on 38 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from September 13, 2021 to present

38
Total CVEs
9
Critical+High
0
Exploited
5
Unpatched

Threat Assessment

Avg CVSS
6.2
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
5
Critical/High
Risk Level
40/100
medium
🆕 1Fresh (<7d)📈 4 in Last 30 Days

Severity Distribution

Critical
4
High
5
Medium
27
Low
1

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
12

Age Distribution

Common Weaknesses (CWE)

1
XSS
13
2
CSRF
5
3
Infoleak
2
4
SQL Injection
2
5
Path Traversal
1

Most Affected Products

1. MotoPress Getwid Wordpress10
2. MotoPress Timetable and Event Schedule WordPress7
3. Getwid Gutenberg Blocks4
4. MotoPress Restaurant Menu by MotoPress3
5. MotoPress Timetable and Event Schedule3

Recent Vulnerabilities

See more →
CVE-2026-15232
unknown

Appointment Booking Lite < 2.4.8 - Unauthenticated Arbitrary Reservation Deletion

Sep 2, 2026🔧 No Patch
CVE-2026-73400
CVSS 8.1high

WordPress Restaurant Menu by MotoPress plugin <= 2.4.11 - Local File Inclusion vulnerability

Aug 18, 2026🔧 No Patch
CVE-2026-15238
CVSS 5.4medium

Hotel Booking Lite < 6.2.3 - Subscriber+ Customer Data Modification via IDOR

Aug 10, 2026🔧 No Patch
CVE-2026-15237
CVSS 5.3medium

Hotel Booking Lite < 6.2.3 - Unauthenticated Payment Record Creation via Checkout Payments REST Endpoint

Aug 10, 2026🔧 No Patch
CVE-2026-15235
CVSS 4.3medium

Hotel Booking Lite < 6.0.4 - Subscriber+ Sensitive Data Disclosure via Admin Calendar AJAX Action

Jul 30, 2026🔧 No Patch
CVE-2026-13454
CVSS 6.5medium

MotoPress Appointment Booking <= 2.4.5 - Authenticated (Staff+) SQL Injection via 's' Parameter

Jul 1, 2026🔧 No Patch
CVE-2026-9228
CVSS 4.3EPSS 0%medium

Timetable and Event Schedule by MotoPress <= 2.4.16 - Insecure Direct Object Reference to Authenticated (Contributor+) Sensitive Information Exposure via action_get_event_data Function

May 28, 2026🔧 No Patch
CVE-2026-8684
CVSS 5.3EPSS 0%medium

MotoPress Hotel Booking <= 6.0.1 - Missing Authorization to Unauthenticated Arbitrary Booking Notes Modification via mphb_update_booking_notes AJAX Action

May 22, 2026🔧 No Patch
CVE-2022-50948
CVSS 5.1medium

Motopress Hotel Booking Lite 4.2.4 Stored Cross-Site Scripting

May 10, 2026🔧 No Patch
CVE-2025-12954
CVSS 2.7low

Timetable and Event Schedule by MotoPress < 2.4.16 - Contributor+ Event Disclosure via IDOR

Dec 3, 2025🔧 No Patch

Monitor motopress in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.

motopress Security Vulnerabilities & Risk Score | 38 CVEs | SecAlerts - SecAlerts