Unauthorized Deletion Vulnerability in MotoPress Appointment Booking Plugin
CVE-2026-15232
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 2 September 2026
Badges
What is CVE-2026-15232?
The MotoPress Appointment Booking WordPress plugin suffers from an improper access control vulnerability that allows unauthenticated attackers to delete other users' reservations. This issue arises due to a lack of necessary authorization checks when processing user-supplied booking identifiers through an unauthenticated endpoint. Although previous fixes were implemented for related vulnerabilities, the exploit remains viable for users on affected versions, particularly those utilizing payment confirmation features.
Affected Version(s)
MotoPress Appointment Booking 0 < 2.4.8
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.