The MotoPress Appointment Booking WordPress plugin before 2.4.8 does not perform an authorization or ownership check when handling a user-supplied booking identifier on an unauthenticated endpoint, allowing unauthenticated attackers to permanently delete other users' reservations. This vulnerability affects site administrators and defenders using the MotoPress Appointment Booking WordPress plugin, who sho [truncated]
CVE-2022-50948 is a stored cross-site scripting issue reported for Motopress Hotel Booking Lite 4.2.4. According to the source corpus, an authenticated attacker can place malicious content into accommodation type title and excerpt fields, and the injected script runs when visitors load the accommodations page. The CVE and NVD entries classify it as medium severity, and no KEV listing was provided.