PatchSiren

MotoPress CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM MotoPress CVE published 2026-09-02

CVE-2026-15232

The MotoPress Appointment Booking WordPress plugin before 2.4.8 does not perform an authorization or ownership check when handling a user-supplied booking identifier on an unauthenticated endpoint, allowing unauthenticated attackers to permanently delete other users' reservations. This vulnerability affects site administrators and defenders using the MotoPress Appointment Booking WordPress plugin, who sho [truncated]

MEDIUM Motopress CVE published 2026-05-10

CVE-2022-50948

CVE-2022-50948 is a stored cross-site scripting issue reported for Motopress Hotel Booking Lite 4.2.4. According to the source corpus, an authenticated attacker can place malicious content into accommodation type title and excerpt fields, and the injected script runs when visitors load the accommodations page. The CVE and NVD entries classify it as medium severity, and no KEV listing was provided.