SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-15232

MEDIUM · CVSS 5.3 EPSS 0.22%

Source: NVD + CISA KEV + EPSS · Published 2026-09-02 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The MotoPress Appointment Booking WordPress plugin prior to version 2.4.8 is vulnerable due to a lack of authorization checks on an unauthenticated endpoint, enabling attackers to delete other users' reservations using a user-supplied booking identifier. This vulnerability poses a risk of data loss and disruption for users relying on the booking system. WordPress site administrators using this plugin should prioritize updating to version 2.4.8 to mitigate the risk.

CVE
CVE-2026-15232
Severity
MEDIUM
CVSS
5.3
EPSS
0.22%
WordPress

Original NVD Description

The MotoPress Appointment Booking WordPress plugin before 2.4.8 does not perform an authorization or ownership check when handling a user-supplied booking identifier on an unauthenticated endpoint, allowing unauthenticated attackers to permanently delete other users' reservations. This is an incomplete fix of CVE-2026-9180: the deletion remains reachable on sites using payment confirmation, confirmed through version 2.4.7.