CVE-2026-15232
Received Received - Intake

Unauthenticated Reservation Deletion in MotoPress Appointment Booking

Vulnerability report for CVE-2026-15232, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-02

Last updated on: 2026-09-02

Assigner: WPScan

Description

The MotoPress Appointment Booking WordPress plugin before 2.4.8 does not perform an authorization or ownership check when handling a user-supplied booking identifier on an unauthenticated endpoint, allowing unauthenticated attackers to permanently delete other users' reservations. This is an incomplete fix of CVE-2026-9180: the deletion remains reachable on sites using payment confirmation, confirmed through version 2.4.7.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-02
Last Modified
2026-09-02
Generated
2026-09-02
AI Q&A
2026-09-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
motopress appointment_booking to 2.4.8 (exc)
motopress appointment_booking 2.4.7

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the WordPress plugin 'Appointment Booking Lite' versions before 2.4.8. It allows unauthenticated attackers to delete arbitrary reservations by exploiting an insecure direct object reference (IDOR) flaw. The plugin fails to perform proper authorization or ownership checks when handling user-supplied booking identifiers on an unauthenticated endpoint.

Detection Guidance

Check if the WordPress plugin 'Appointment Booking Lite' is installed and verify its version. If the version is prior to 2.4.8, the system is vulnerable. Look for unauthorized deletion of reservations in logs or user reports.

Impact Analysis

Unauthenticated attackers can permanently delete other users' reservations, leading to data loss and disruption of booking services. This can affect businesses relying on the plugin for appointment management.

Compliance Impact

This vulnerability could potentially violate compliance with GDPR and HIPAA due to unauthorized data deletion. GDPR requires organizations to ensure data integrity and security, while HIPAA mandates protection of patient records. Unauthorized deletion of reservations may constitute a breach of these regulations, depending on the data involved.

Mitigation Strategies

Update the 'Appointment Booking Lite' plugin to version 2.4.8 or later immediately. If an update is not available, consider disabling the plugin temporarily until a patch is released.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-15232. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart