plugin

Motopress Hotel Booking Lite Vulnerabilities

12 known security issues reported for the Motopress Hotel Booking Lite WordPress plugin. Most recent disclosed Aug 6, 2026.

2 critical 6 medium

Running Motopress Hotel Booking Lite on your site? Check whether your installed version is affected.

Scan your site free

Hotel Booking Lite <= 6.2.2 - Insecure Direct Object Reference to Authenticated (Subscriber+) Customer Data Modification

medium

The Hotel Booking Lite plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 6.2.2. This is due to missing ownership verification on the customer_id parameter, allowing the customer record to be fetched directly from POST data without confirming it belongs to the authe...

CVSS:
4.3
Affected:
up to 6.2.2
Fixed in:
6.2.3
Disclosed:
Aug 6, 2026

CVE-2026-15238 on NVD →

MotoPress Hotel Booking < 6.0.4 - Authenticated (Subscriber+) Information Exposure

medium

The MotoPress Hotel Booking plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to 6.0.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract sensitive user or configuration data.

CVSS:
4.3
Affected:
up to 6.0.4
Fixed in:
6.0.4
Disclosed:
Aug 3, 2026

CVE-2026-15235 on NVD →

MotoPress Hotel Booking <= 6.0.3 - Authenticated (Subscriber+) Information Exposure

medium

The MotoPress Hotel Booking plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.0.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to extract sensitive user or configuration data.

CVSS:
4.3
Affected:
up to 6.0.3
Fixed in:
6.0.4
Disclosed:
Jul 1, 2026

CVE-2026-57347 on NVD →

MotoPress Hotel Booking <= 6.0.1 - Missing Authorization to Unauthenticated Arbitrary Booking Notes Modification via mphb_update_booking_notes AJAX Action

medium

The MotoPress Hotel Booking plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.0.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to overwrite or delete the internal no...

CVSS:
5.3
Affected:
up to 6.0.1
Fixed in:
6.0.2
Disclosed:
May 21, 2026

CVE-2026-8684 on NVD →

MotoPress Hotel Booking [motopress-hotel-booking-lite] <= 5.2.3 (unfixed)

unknown

[en] Improper Control of Generation of Code ('Code Injection') vulnerability in jetmonsters Hotel Booking Lite motopress-hotel-booking-lite allows Remote Code Inclusion.This issue affects Hotel Booking Lite: from n/a through <= 5.2.3.

Affected:
up to 5.2.3
Fix:
No patched version reported
Disclosed:
Dec 18, 2025

CVE-2025-66078 on NVD →

Hotel Booking Lite <= 5.2.3 - Authenticated (Hotel Worker+) Remote Code Execution

medium

The MotoPress Hotel Booking plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 5.2.3. This makes it possible for authenticated attackers, with Hotel Worker-level access and above, to execute code on the server.

CVSS:
5.3
Affected:
up to 5.2.3
Fixed in:
5.2.4
Disclosed:
Nov 25, 2025

CVE-2025-66078 on NVD →

Hotel Booking Lite <= 4.11.1 - Unauthenticated PHP Object Injection

critical

The Hotel Booking Lite plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.11.1 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable plugin. If a POP chain is pr...

CVSS:
9.8
Affected:
up to 4.11.1
Fixed in:
4.11.2
Disclosed:
May 10, 2024

CVE-2024-4413 on NVD →

MotoPress Hotel Booking [motopress-hotel-booking-lite] < 4.11.2

unknown

[en] The Hotel Booking Lite plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.11.1 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable plugin. If a POP chain...

Affected:
up to 4.11.2
Fixed in:
4.11.2
Disclosed:
May 10, 2024

CVE-2024-4413 on NVD →

MotoPress Hotel Booking [motopress-hotel-booking-lite] < 4.8.5

unknown

[en] The Hotel Booking Lite WordPress plugin before 4.8.5 does not validate file paths provided via user input, as well as does not have proper CSRF and authorisation checks, allowing unauthenticated users to download and delete arbitrary files on the server

Affected:
up to 4.8.5
Fixed in:
4.8.5
Disclosed:
Dec 26, 2023

CVE-2023-5991 on NVD →

Hotel Booking Lite <= 4.8.4 - Insufficient Path Validation to Unauthenticated Arbitrary File Deletion and Download

critical

The Hotel Booking Lite plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the maybeDownload() function and insufficient path validation in all versions up to 4.8.5 (exclusive). This makes it possible for unauthenticated to retrieve and delete arbitrary files whi...

CVSS:
9.8
Affected:
up to 4.8.5
Fixed in:
4.8.5
Disclosed:
Dec 1, 2023

CVE-2023-5991 on NVD →

MotoPress Hotel Booking [motopress-hotel-booking-lite] < 4.7.0

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in MotoPress Hotel Booking Lite plugin <= 4.6.0 versions.

Affected:
up to 4.7.0
Fixed in:
4.7.0
Disclosed:
Nov 12, 2023

CVE-2023-28498 on NVD →

Hotel Booking Lite <= 4.6.0 - Cross-Site Request Forgery to Settings Update

medium

The Hotel Booking Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.6.0. This is due to missing or incorrect nonce validation on the 'render' and 'onLoad' functions. This makes it possible for unauthenticated attackers to update plugin settings like booking rules,...

CVSS:
4.3
Affected:
up to 4.6.0
Fixed in:
4.7.0
Disclosed:
Mar 16, 2023

CVE-2023-28498 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database