Unauthorized Deletion Vulnerability in MotoPress Appointment Booking Plugin
CVE-2026-15232

Currently unrated

Key Information:

Vendor

WordPress

Vendor
CVE Published:
2 September 2026

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2026-15232?

The MotoPress Appointment Booking WordPress plugin suffers from an improper access control vulnerability that allows unauthenticated attackers to delete other users' reservations. This issue arises due to a lack of necessary authorization checks when processing user-supplied booking identifiers through an unauthenticated endpoint. Although previous fixes were implemented for related vulnerabilities, the exploit remains viable for users on affected versions, particularly those utilizing payment confirmation features.

Affected Version(s)

MotoPress Appointment Booking 0 < 2.4.8

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ahmed Hashim Ismael
WPScan
.