← Back to CVE Registry
CVE-2026-152385.4medium[patched]
Subscriber+ Customer Data Modification via IDOR
TARGET ECOSYSTEM / VENDORMotoPress
AFFECTED PRODUCTHotel Booking Lite (< 6.2.3)
CWE CLASSIFICATIONCWE-639: Insecure Direct Object Reference
PUBLISHED DATE2026-08-06
ADVISORY / CNAWPScan Advisory (CNA) ↗
Summary
Hotel Booking Lite (< 6.2.3) does not verify record ownership before updating customer records. This allows any authenticated user with a low-privileged account (Subscriber and above) to modify or overwrite the personal data of any customer by supplying an arbitrary identifier.
Vulnerability Analysis
The vulnerability exists in the account shortcode handler (mphb_action=update_customer). The plugin directly accepts customer_id from $_POST without verifying that the targeted record belongs to the active session user, while relying on an unbound generic nonce (action=-1).
Fixed In
Fixed in version 6.2.3 by retrieving records strictly by authenticated session user ID (findByUserId($userId)).