{"id":"CVE-2026-15237","title":"The MotoPress Hotel Booking WordPress plugin before 6.2.3 does not perform any authorization or ownership check on a REST endpoint that creates payment records, allowing unauthenticated users to create completed payment records against a…","summary":"The MotoPress Hotel Booking WordPress plugin before 6.2.3 does not perform any authorization or ownership check on a REST endpoint that creates payment records, allowing unauthenticated users to create completed payment records against a…","severity":"none","published":"2026-08-10","updated":"2026-08-10","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-15237","references":[{"url":"https://wpscan.com/vulnerability/b312a323-808c-497f-b67e-3b0acfcb8932/","label":"contact@wpscan.com"}],"tags":["nvd"],"ingestedAt":"2026-08-10T07:39:17.719Z","epss":0.00221,"epssPercentile":0.12898,"slug":"CVE-2026-15237","body":"## Overview\n\nThe MotoPress Hotel Booking WordPress plugin before 6.2.3 does not perform any authorization or ownership check on a REST endpoint that creates payment records, allowing unauthenticated users to create completed payment records against arbitrary bookings and falsely mark them as paid.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}