CVE-2026-15238: Hotel Booking Lite < 6.2.3 - Subscriber+ Customer Data Modification via IDOR
The MotoPress Hotel Booking WordPress plugin before 6.2.3 does not verify record ownership before updating customer records, allowing any authenticated user with a low-privileged account (Subscriber and above) to modify or overwrite the personal data of any customer by supplying an arbitrary identifier.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
MotoPress Hotel Booking WordPress pluginto a version that resolves this vulnerability.Fixed in 6.2.3 - Compensating control
Restrict access so that only users with higher privileges than Subscriber can update/trigger customer record modifications (reduce the ability of low-privileged authenticated users to exploit the IDOR issue).
Event History
Frequently Asked Questions
What is the severity of CVE-2026-15238?
CVE-2026-15238 has a risk rating of 57, indicating a moderate severity vulnerability.
How do I fix CVE-2026-15238?
To fix CVE-2026-15238, update the MotoPress Hotel Booking WordPress plugin to version 6.2.3 or later.
Who is affected by CVE-2026-15238?
CVE-2026-15238 affects any authenticated user with a low-privileged account, such as Subscriber and above.
What kind of vulnerability is CVE-2026-15238?
CVE-2026-15238 is an Insecure Direct Object Reference (IDOR) vulnerability that allows unauthorized modification of customer data.
What are the implications of CVE-2026-15238?
The implications of CVE-2026-15238 include potential unauthorized access and modification of personal customer data.