CVE-2026-8684: MotoPress Hotel Booking <= 6.0.1 - Missing Authorization to Unauthenticated Arbitrary Booking Notes Modification via mphb_update_booking_notes AJAX Action
The MotoPress Hotel Booking plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.0.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to overwrite or delete the internal notes (mphbbookinginternalnotes) of any booking by supplying an arbitrary booking ID. The nonce for this action is output in the HTML source of every public page through wplocalizescript (MPHB.data.nonces), so any unauthenticated visitor can obtain a valid nonce and perform the action without any account or prior interaction.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-8684?
The severity of CVE-2026-8684 is medium with a score of 5.3.
What vulnerability is associated with CVE-2026-8684?
CVE-2026-8684 is associated with an authorization bypass in the MotoPress Hotel Booking plugin for WordPress.
How do I fix CVE-2026-8684?
To fix CVE-2026-8684, you should update the MotoPress Hotel Booking plugin to the latest version beyond 6.0.1.
Can CVE-2026-8684 be exploited by unauthenticated users?
Yes, CVE-2026-8684 can be exploited by unauthenticated attackers who can modify booking notes.
What should I do if I am using MotoPress Hotel Booking version 6.0.1 or earlier?
If using MotoPress Hotel Booking version 6.0.1 or earlier, you should update to the latest version immediately to mitigate the vulnerability.