WordPress security changelog
MEDIUM CVE-2026-15232 Deferred

MotoPress Appointment Booking permits unauthenticated reservation deletion

MotoPress Appointment Booking before 2.4.8 does not authorize or verify ownership of a user-supplied booking ID on an unauthenticated endpoint. An attacker can permanently delete another user's reservation. This is an incomplete fix of CVE-2026-9180 and remains reachable through 2.4.7 on sites using payment confirmation.

CVE / CNA score 5.3 CVSS 3.1 · 134c704f-9b21-4f2e-91b3-4a467353bcc0
NVD score Pending NVD has not published its own CVSS assessment.
Component
MotoPress Appointment Booking
Plugin slug
motopress-appointment-lite
Affected
< 2.4.8
Safe version
2.4.8
Published
Sep 02, 2026
Weakness
CWE-639 — Authorization Bypass Through User-Controlled Key

This CVE was published Sep 02, 2026 and is one of 3 known issues for this plugin.

Update, patch or deactivate.

Update to MotoPress Appointment Booking 2.4.8 or later and reconcile bookings and payment confirmations for unexpected deletions.

A safe version is available, so updating to that version or later is the preferred remediation. If an immediate update is not practical, consider a targeted application patch or temporarily restricting the affected functionality.

Deactivate only when warranted by your risk profile, or when advised by your hosting provider in the limited circumstances where the vulnerability cannot otherwise be mitigated. If you’re unsure which action is appropriate, contact Fused or your hosting provider for guidance.

Technical description

The MotoPress Appointment Booking WordPress plugin before 2.4.8 does not perform an authorization or ownership check when handling a user-supplied booking identifier on an unauthenticated endpoint, allowing unauthenticated attackers to permanently delete other users' reservations. This is an incomplete fix of CVE-2026-9180: the deletion remains reachable on sites using payment confirmation, confirmed through version 2.4.7.

CVE / CNA vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Primary and upstream sources