CVE-2026-9180 | jetmonsters MotoPress Appointment Booking Plugin up to 2.4.4 on WordPress REST Endpoint bookings findById payment_details.booking_id authorization (EUVD-2026-41492)

SecurityVulns

A vulnerability classified as critical has been found in jetmonsters MotoPress Appointment Booking Plugin up to 2.4.4 on WordPress. The impacted element is the function findById of the file /motopress/appointment/v1/bookings of the component REST Endpoint. Performing a manipulation of the argument payment_details.booking_id results in authorization bypass.

This vulnerability was named CVE-2026-9180. The attack may be initiated remotely. There is no available exploit.VulDB Recent EntriesRead More