CVE-2026-15235: Hotel Booking Lite < 6.0.4 - Subscriber+ Sensitive Data Disclosure via Admin Calendar AJAX Action
The MotoPress Hotel Booking WordPress plugin before 6.0.4 does not perform a capability check before returning a booking's full customer details in one of its AJAX actions, allowing any authenticated user with a low-privileged account (Subscriber and above) to read the personal data, including name, email, phone, and address, of any customer.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-15235?
The severity of CVE-2026-15235 is classified as medium with a CVSS score of 4.3.
How do I fix CVE-2026-15235?
To fix CVE-2026-15235, update the MotoPress Hotel Booking plugin to version 6.0.4 or later.
What types of data are disclosed by CVE-2026-15235?
CVE-2026-15235 allows unauthorized access to sensitive customer data, including personal details like names.
Who is affected by CVE-2026-15235?
Any authenticated user with a low-privileged account, such as Subscriber and above, is affected by CVE-2026-15235.
What is the impact of CVE-2026-15235?
The impact of CVE-2026-15235 is a risk of unauthorized data exposure due to lack of proper capability checks.