Medium severity4.3NVD Advisory· Published Jul 30, 2026· Updated Jul 30, 2026
CVE-2026-15235
CVE-2026-15235
Description
The MotoPress Hotel Booking WordPress plugin before 6.0.4 does not perform a capability check before returning a booking's full customer details in one of its AJAX actions, allowing any authenticated user with a low-privileged account (Subscriber and above) to read the personal data, including name, email, phone, and address, of any customer.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <6.0.4
Patches
Vulnerability mechanics
References
1News mentions
1- Wordfence Intelligence Weekly WordPress Vulnerability Report (August 3, 2026 to August 9, 2026)Wordfence Blog · Aug 14, 2026