PoC Index82,564 CVEs with PoCs

CVE-2026-15232

Appointment Booking Lite < 2.4.8 - Unauthenticated Arbitrary Reservation Deletion

MEDIUM 5.3EPSS 0.2%

The MotoPress Appointment Booking WordPress plugin before 2.4.8 does not perform an authorization or ownership check when handling a user-supplied booking identifier on an unauthenticated endpoint, allowing unauthenticated attackers to permanently delete other users' reservations. This is an incomplete fix of CVE-2026-9180: the deletion remains reachable on sites using payment confirmation, confirmed through version 2.4.7.

Affected
MotoPress Appointment Booking
CVSS v3.1 CNA
5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
EPSS
0.22% chance of exploitation in the next 30 days, 12th percentile
Published
2026-09-02

Proof-of-concept exploits (1)

References