WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in MotoPress Hotel Booking

The #1 Hotel Booking and Vacation Rental Plugin for WordPress. Online payments, seasons, rates, free or paid extras, coupons, taxes & fees.

7Reported vulnerabilities
9.8Highest CVSS score
6.2.3Latest version
10,000+Active installs

What to do now

Update MotoPress Hotel Booking to 6.2.3 or later. 7 of these have a fixed version available. Updating resolves them.

Plugin last updated: August 3, 2026 / Tested up to WordPress: 6.9.7 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
CVE-2024-4413 Critical 9.8 0.9% 0 to 4.11.1 (inclusive)
0 to 4.11.1 (inclusive)
4.11.2 May 14, 2024
CVE-2026-8684 Medium 5.3 0.3% 0 to 6.0.1 (inclusive) 6.0.2 May 22, 2026
CVE-2025-66078 Medium 5.3 0.4% 5.2.3 and earlier 5.2.4 November 25, 2025
CVE-2026-15238 Medium 4.3 0.2% 6.2.2 and earlier 6.2.3 August 6, 2026
CVE-2026-15235 Medium 4.3 0.2% Before 6.0.4 6.0.4 August 3, 2026
CVE-2026-57347 Medium 4.3 0.4% 6.0.3 and earlier 6.0.4 July 1, 2026
CVE-2023-28498 Medium 4.3 0.3% 4.6.0 and earlier 4.7.0 March 16, 2023

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.