SecAlerts
motopress logo

motopress

Security Risk Profile

39
/100
low

Security Risk Score

Comprehensive risk assessment based on 36 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from September 13, 2021 to present

36
Total CVEs
8
Critical+High
0
Exploited
4
Unpatched

Threat Assessment

Avg CVSS
6.2
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
4
Critical/High
Risk Level
39/100
low
🆕 2Fresh (<7d)📈 3 in Last 30 Days

Severity Distribution

Critical
4
High
4
Medium
25
Low
1

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
12

Age Distribution

Common Weaknesses (CWE)

1
XSS
13
2
CSRF
5
3
Infoleak
2
4
SQL Injection
2
5
Path Traversal
1

Most Affected Products

1. MotoPress Getwid Wordpress10
2. MotoPress Timetable and Event Schedule WordPress7
3. Getwid Gutenberg Blocks4
4. MotoPress Timetable and Event Schedule3
5. MotoPress Restaurant Menu by MotoPress2

Recent Vulnerabilities

See more →
CVE-2026-15238
unknown

Hotel Booking Lite < 6.2.3 - Subscriber+ Customer Data Modification via IDOR

8/10/2026🔧 No Patch
CVE-2026-15237
unknown

Hotel Booking Lite < 6.2.3 - Unauthenticated Payment Record Creation via Checkout Payments REST Endpoint

8/10/2026🔧 No Patch
CVE-2026-15235
CVSS 4.3medium

Hotel Booking Lite < 6.0.4 - Subscriber+ Sensitive Data Disclosure via Admin Calendar AJAX Action

7/30/2026🔧 No Patch
CVE-2026-13454
CVSS 6.5medium

MotoPress Appointment Booking <= 2.4.5 - Authenticated (Staff+) SQL Injection via 's' Parameter

7/1/2026🔧 No Patch
CVE-2026-9228
CVSS 4.3EPSS 0%medium

Timetable and Event Schedule by MotoPress <= 2.4.16 - Insecure Direct Object Reference to Authenticated (Contributor+) Sensitive Information Exposure via action_get_event_data Function

5/28/2026🔧 No Patch
CVE-2026-8684
CVSS 5.3EPSS 0%medium

MotoPress Hotel Booking <= 6.0.1 - Missing Authorization to Unauthenticated Arbitrary Booking Notes Modification via mphb_update_booking_notes AJAX Action

5/22/2026🔧 No Patch
CVE-2022-50948
CVSS 5.1medium

Motopress Hotel Booking Lite 4.2.4 Stored Cross-Site Scripting

5/10/2026🔧 No Patch
CVE-2025-12954
CVSS 2.7low

Timetable and Event Schedule by MotoPress < 2.4.16 - Contributor+ Event Disclosure via IDOR

12/3/2025🔧 No Patch
CVE-2025-54038
CVSS 5.4medium

WordPress Restaurant Menu by MotoPress plugin <= 2.4.6 - Cross Site Request Forgery (CSRF) Vulnerability

7/16/2025
CVE-2025-30846
CVSS 8.8EPSS 0%high

WordPress Restaurant Menu by MotoPress plugin <= 2.4.4 - Local File Inclusion vulnerability

3/27/2025

Monitor motopress in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.

motopress Security Vulnerabilities & Risk Score | 36 CVEs | SecAlerts - SecAlerts