CVE-2026-90650 | MotoPress Hotel Booking Plugin up to 6.2.4 on WordPress Stripe Webhook webhook-listener.php ID cross site scripting
A vulnerability identified as problematic has been detected in MotoPress Hotel Booking Plugin up to 6.2.4 on WordPress. This vulnerability affects unknown code of the file webhook-listener.php of the component Stripe Webhook. The manipulation of the argument ID leads to cross site scripting.
This vulnerability is documented as CVE-2026-90650. The attack can be initiated remotely. There is not any exploit available.VulDB Recent EntriesRead More