PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-8684 jetmonsters CVE debrief

The MotoPress Hotel Booking plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.0.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to overwrite or delete the internal notes (_mphb_booking_internal_notes) of any booking by supplying an arbitrary booking ID. The vulnerability has a CVSS score of 5.3 and a severity of MEDIUM. Administrators of WordPress installations using the MotoPress Hotel Booking plugin should prioritize updating to a patched version.

Vendor
jetmonsters
Product
MotoPress Hotel Booking
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-22
Original CVE updated
2026-07-23
Advisory published
2026-05-22
Advisory updated
2026-07-23

Who should care

Administrators of WordPress installations using the MotoPress Hotel Booking plugin, especially those allowing public access or with high-traffic sites, should prioritize updating to a patched version. Additionally, security teams and vulnerability management teams should review the vulnerability and its impact on their organization's WordPress installations.

Technical summary

The MotoPress Hotel Booking plugin for WordPress has an authorization bypass vulnerability. The plugin fails to properly verify user authorization for certain actions, allowing unauthenticated attackers to manipulate booking notes by providing an arbitrary booking ID. This vulnerability exists in all versions up to and including 6.0.1. The vulnerability can be exploited by unauthenticated attackers, making it a significant concern for WordPress installations using the plugin. The plugin's failure to verify user authorization allows attackers to overwrite or delete internal notes of any booking.

Defensive priority

Medium priority due to the potential for data manipulation by unauthenticated attackers. However, the priority may be elevated for high-traffic sites or those with sensitive data.

Recommended defensive actions

  • Update the MotoPress Hotel Booking plugin to a version beyond 6.0.1.
  • Review and monitor internal notes for any unauthorized changes.
  • Implement additional access controls and monitoring for WordPress installations using the plugin.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.

Evidence notes

The vulnerability was reported by [email protected]. The CVE record was published on 2026-05-22T09:16:33.033Z and last modified on 2026-07-23T16:10:00.137Z. The evidence provided by [email protected] indicates that the MotoPress Hotel Booking plugin for WordPress has an authorization bypass vulnerability. This vulnerability allows unauthenticated attackers to overwrite or delete internal notes of any booking by supplying an arbitrary booking ID. The plugin fails to properly verify user authorization for certain actions, making it possible for attackers to manipulate booking notes. The CVE record and NVD details provide additional context on the vulnerability and its impact.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-05-22T09:16:33.033Z and has not been modified since then.