CyberRota Analysis
AI-GeneratedThe MotoPress Appointment Booking WordPress plugin prior to version 2.4.8 is vulnerable due to a lack of authorization checks on an unauthenticated endpoint, enabling attackers to delete other users' reservations using a user-supplied booking identifier. This vulnerability poses a risk of data loss and disruption for users relying on the booking system. WordPress site administrators using this plugin should prioritize updating to version 2.4.8 to mitigate the risk.
Original NVD Description
The MotoPress Appointment Booking WordPress plugin before 2.4.8 does not perform an authorization or ownership check when handling a user-supplied booking identifier on an unauthenticated endpoint, allowing unauthenticated attackers to permanently delete other users' reservations. This is an incomplete fix of CVE-2026-9180: the deletion remains reachable on sites using payment confirmation, confirmed through version 2.4.7.