haitam lazaar / lazaarsec
← Back to CVE Registry
CVE-2026-152375.3medium[patched]

Unauthenticated Payment Record Creation via Checkout REST Endpoint

TARGET ECOSYSTEM / VENDORMotoPress
AFFECTED PRODUCTHotel Booking Lite (< 6.2.3)
CWE CLASSIFICATIONCWE-284: Improper Access Control
PUBLISHED DATE2026-08-06

Summary

Hotel Booking Lite (< 6.2.3) does not perform any authorization or ownership check on a REST endpoint that creates payment records. This allows unauthenticated users to create completed payment records against arbitrary bookings and falsely mark them as paid.

Vulnerability Analysis

The plugin exposes a REST API endpoint at /wp-json/mphb/v1/checkout/payments that allows unauthenticated users to create payment records against any existing booking. SubmitPaymentController::is_request_allowed() unconditionally returned true without checking nonces or booking ownership.

Fixed In

Fixed in version 6.2.3 with strict nonce verification cryptographically bound to booking keys.