Where
-Infinity
0

MotoPress Hotel Booking WordPress pluginHotel Booking Lite < 6.2.3 - Subscriber+ Customer Data Modification via IDOR

Risk 57
First published (updated )

MotoPress Hotel Booking WordPress plugin (Hotel Booking Lite)Hotel Booking Lite < 6.2.3 - Unauthenticated Payment Record Creation via Checkout Payments REST Endpoint

Risk 67
First published (updated )

MotoPress Hotel BookingHotel Booking Lite < 6.0.4 - Subscriber+ Sensitive Data Disclosure via Admin Calendar AJAX Action

Risk 22
Severity
4.3
First published (updated )

MotoPress Appointment Booking (WordPress plugin)MotoPress Appointment Booking <= 2.4.5 - Authenticated (Staff+) SQL Injection via 's' Parameter

Risk 38
Severity
6.5
First published (updated )

MotoPress Timetable and Event ScheduleTimetable and Event Schedule by MotoPress <= 2.4.16 - Insecure Direct Object Reference to Authenticated (Contributor+) Sensitive Information Exposure via action_get_event_data Function

Risk 16
Severity
4.3
EPSS
0.22%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

MotoPress MotoPress Hotel BookingMotoPress Hotel Booking <= 6.0.1 - Missing Authorization to Unauthenticated Arbitrary Booking Notes Modification via mphb_update_booking_notes AJAX Action

Risk 19
Severity
5.3
EPSS
0.28%
First published (updated )

MotoPress MotoPress Hotel Booking LiteMotopress Hotel Booking Lite 4.2.4 Stored Cross-Site Scripting

Risk 39
Severity
5.1
First published (updated )

MotoPress Timetable and Event ScheduleTimetable and Event Schedule by MotoPress < 2.4.16 - Contributor+ Event Disclosure via IDOR

Risk 16
Severity
2.7
First published (updated )

MotoPress Restaurant Menu by MotoPressWordPress Restaurant Menu by MotoPress plugin <= 2.4.6 - Cross Site Request Forgery (CSRF) Vulnerability

Risk 34
Severity
5.4
First published (updated )

MotoPress Restaurant Menu by MotoPressWordPress Restaurant Menu by MotoPress plugin <= 2.4.4 - Local File Inclusion vulnerability

Risk 35
Severity
8.8
EPSS
0.13%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

MotoPress Stratum WordpressStratum – Elementor Widgets <= 1.4.7 - Authenticated (Contributor+) Stored Cross-Site Scripting Vulnerability via Image Hotspot Widget

Risk 39
Severity
6.4
First published (updated )

MotoPress Getwid WordpressGetwid – Gutenberg Blocks <= 2.0.12 - Authenticated (Contributor+) Stored Cross-Site Scripting

Risk 39
Severity
6.4
First published (updated )

MotoPress Timetable and Event Schedule WordPressTimetable and Event Schedule by MotoPress <= 2.3.8 - Missing Authorization

Risk 86
Severity
9.8
First published (updated )

MotoPress Timetable and Event ScheduleWordPress Timetable and Event Schedule by MotoPress plugin <= 2.4.13 - PHP Object Injection vulnerability

Risk 39
Severity
5.5
First published (updated )

MotoPress Getwid WordpressGetwid – Gutenberg Blocks <= 2.0.10 - Missing Authorization to Google API key update

Risk 19
Severity
5.3
EPSS
0.05%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

MotoPress Getwid WordpressGetwid – Gutenberg Blocks <= 2.0.10 - Missing Authentication to MailChimp API key update

Risk 16
Severity
4.3
EPSS
0.05%
First published (updated )

MotoPress Getwid WordpressGetwid – Gutenberg Blocks <= 2.0.7 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via 'Countdown'

Risk 28
Severity
6.4
EPSS
0.07%
First published (updated )

MotoPress Timetable and Event Schedule by MotoPressTimetable and Event Schedule by MotoPress <= 2.4.11 - Authenticated (Contributor+) SQL Injection

Risk 59
Severity
9.9
EPSS
0.05%
First published (updated )

MotoPress Getwid WordpressGetwid – Gutenberg Blocks <= 2.0.5 - Authenticated(Contributor+) Stored Cross-Site Scripting via Block Content

Risk 39
Severity
6.4
First published (updated )

MotoPress Stratum – Elementor WidgetsWordPress Stratum – Elementor Widgets plugin <= 1.3.15 - Cross Site Scripting (XSS) vulnerability

Risk 34
Severity
6.5
EPSS
0.04%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

MotoPress Getwid WordpressGetwid – Gutenberg Blocks <= 2.0.4 - Captcha Bypass

Risk 19
Severity
5.3
EPSS
0.05%
First published (updated )

MotoPress Getwid WordpressGetwid – Gutenberg Blocks <= 2.0.4 - Missing Authorization to Recaptcha API Key Modification

Risk 16
Severity
4.3
EPSS
0.04%
First published (updated )

MotoPress Getwid WordpressGetwid < 2.0.3 - Unauthenticated Arbitrary Email Sending to Admin

Risk 31
Severity
7.5
EPSS
0.11%
First published (updated )

MotoPress Hotel Booking Lite WordpressHotel Booking Lite < 4.8.5 - Unauthenticated Arbitrary File Download & Deletion

Risk 61
Severity
9.8
EPSS
0.60%
First published (updated )

MotoPress Jetblocks For Elementor WordpressWordPress JetBlocks For Elementor Plugin <= 1.3.8 is vulnerable to Cross Site Scripting (XSS)

Risk 50
Severity
7.1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

MotoPress Hotel Booking Lite WordpressWordPress Hotel Booking Lite Plugin <= 4.6.0 is vulnerable to Cross Site Request Forgery (CSRF)

Risk 77
Severity
8.8
First published (updated )

MotoPress Getwid WordpressGetwid – Gutenberg Blocks <= 1.8.3 - Authenticated(Subscriber+) Server Side Request Forgery

Risk 68
Severity
9.6
First published (updated )

MotoPress Getwid - Gutenberg Blocks WordpressGetwid – Gutenberg Blocks <= 1.8.3 - Improper Authorization via get_remote_templates REST endpoint

Risk 23
Severity
4.3
First published (updated )

MotoPress Timetable and Event Schedule WordPressMotoPress Timetable and Event Schedule Calendar cross site scripting

Risk 38
Severity
6.1
First published (updated )

MotoPress Timetable and Event Schedule WordPressMotoPress Timetable and Event Schedule Quick Edit admin-ajax.php cross site scripting

Risk 38
Severity
6.1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203