MotoPress Appointment Booking permits unauthenticated reservation deletion
MotoPress Appointment Booking before 2.4.8 does not authorize or verify ownership of a user-supplied booking ID on an unauthenticated endpoint. An attacker can permanently delete another user's reservation. This is an incomplete fix of CVE-2026-9180 and remains reachable through 2.4.7 on sites using payment confirmation.
- Component
- MotoPress Appointment Booking
- Plugin slug
motopress-appointment-lite- Affected
- < 2.4.8
- Safe version
2.4.8- Published
- Sep 02, 2026
This CVE was published Sep 02, 2026 and is one of 3 known issues for this plugin.
Update, patch or deactivate.
Update to MotoPress Appointment Booking 2.4.8 or later and reconcile bookings and payment confirmations for unexpected deletions.
A safe version is available, so updating to that version or later is the preferred remediation. If an immediate update is not practical, consider a targeted application patch or temporarily restricting the affected functionality.
Deactivate only when warranted by your risk profile, or when advised by your hosting provider in the limited circumstances where the vulnerability cannot otherwise be mitigated. If you’re unsure which action is appropriate, contact Fused or your hosting provider for guidance.
Technical description
The MotoPress Appointment Booking WordPress plugin before 2.4.8 does not perform an authorization or ownership check when handling a user-supplied booking identifier on an unauthenticated endpoint, allowing unauthenticated attackers to permanently delete other users' reservations. This is an incomplete fix of CVE-2026-9180: the deletion remains reachable on sites using payment confirmation, confirmed through version 2.4.7.
CVE / CNA vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N