plugin

Motopress Appointment Lite Vulnerabilities

2 known security issues reported for the Motopress Appointment Lite WordPress plugin. Most recent disclosed Jul 2, 2026.

2 medium

Running Motopress Appointment Lite on your site? Check whether your installed version is affected.

Scan your site free

MotoPress Appointment Booking <= 2.4.4 - Unauthenticated Insecure Direct Object Reference to 'payment_details.booking_id' Parameter

medium

The MotoPress Appointment Booking plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in all versions up to, and including, 2.4.4. This is due to the `POST /motopress/appointment/v1/bookings` REST endpoint being registered with `'permission_callback' => '__return_true'`, allowing unau...

CVSS:
5.3
Affected:
up to 2.4.4
Fixed in:
2.4.5
Disclosed:
Jul 2, 2026

CVE-2026-9180 on NVD →

MotoPress Appointment Booking <= 2.4.5 - Authenticated (Staff+) SQL Injection via 's' Parameter

medium

The MotoPress Appointment Booking plugin for WordPress is vulnerable to generic SQL Injection via the 's' parameter in all versions up to, and including, 2.4.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticat...

CVSS:
6.5
Affected:
up to 2.4.5
Fixed in:
2.4.6
Disclosed:
Jun 30, 2026

CVE-2026-13454 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database