CVE-2026-15237: Hotel Booking Lite < 6.2.3 - Unauthenticated Payment Record Creation via Checkout Payments REST Endpoint
The MotoPress Hotel Booking WordPress plugin before 6.2.3 does not perform any authorization or ownership check on a REST endpoint that creates payment records, allowing unauthenticated users to create completed payment records against arbitrary bookings and falsely mark them as paid.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-15237?
CVE-2026-15237 has a risk score of 67, indicating a moderate severity vulnerability.
How do I fix CVE-2026-15237?
To fix CVE-2026-15237, update the MotoPress Hotel Booking plugin to version 6.2.3 or later, which resolves the unauthorized payment record creation issue.
What does CVE-2026-15237 allow attackers to do?
CVE-2026-15237 allows unauthenticated users to create completed payment records for arbitrary bookings, falsely marking them as paid.
Which software is affected by CVE-2026-15237?
CVE-2026-15237 affects the MotoPress Hotel Booking WordPress plugin versions prior to 6.2.3.
What version of the plugin resolves CVE-2026-15237?
CVE-2026-15237 is resolved in MotoPress Hotel Booking plugin version 6.2.3 and later.