Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4356 articles · 196341 vulns · 36/41 feeds (7d)
← Back to list
6.5
CVE-2026-13454EXPLOITED
jetmonsters · motopress appointment booking

MotoPress Appointment Booking <= 2.4.5 - Authenticated (Staff+) SQL Injection via 's' Parameter

Description

The MotoPress Appointment Booking plugin for WordPress is vulnerable to generic SQL Injection via the 's' parameter in all versions up to, and including, 2.4.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with custom-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. Exploitation requires the mpa_appointment_employee custom role, meaning any user assigned this role can perform the attack.

Affected Products

VendorProductVersions
jetmonstersmotopress appointment booking0

References

  • https://www.wordfence.com/threat-intel/vulnerabilities/id/64e4d51a-7b65-4fba-9742-bc7d23f46f8d?source=cve
  • https://plugins.trac.wordpress.org/browser/motopress-appointment-lite/tags/2.4.5/includes/admin-pages/manage/ManageBookingsPage.php#L310
  • https://plugins.trac.wordpress.org/browser/motopress-appointment-lite/tags/2.4.5/includes/admin-pages/manage/ManageBookingsPage.php#L247
  • https://plugins.trac.wordpress.org/browser/motopress-appointment-lite/tags/2.4.3/includes/admin-pages/manage/ManageBookingsPage.php#L310
  • https://plugins.trac.wordpress.org/browser/motopress-appointment-lite/tags/2.4.3/includes/admin-pages/manage/ManageBookingsPage.php#L247
  • https://plugins.trac.wordpress.org/changeset/3591693/motopress-appointment-lite/trunk/includes/admin-pages/manage/ManageBookingsPage.php

Related News (1 articles)

Tier C
VulDB53d ago
CVE-2026-13454 | jetmonsters MotoPress Appointment Booking Plugin up to 2.4.5 on WordPress sql injection
→ No new info (linked only)
CVSS 3.16.5 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CISA KEV❌ No
Actively exploited✅ Yes
CWECWE-89
PublishedJul 1, 2026
Last enriched53d agov2
Trending Score0
Source articles1
Independent1
Info Completeness8/14
Missing: epss, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-73400EXPKEV
WordPress Restaurant Menu by MotoPress plugin <= 2.4.11 - Local File Inclusion vulnerability
Trending: 45
HIGHCVE-2026-28140
WordPress JetFormBuilder plugin <= 3.6.4.1 - Broken Access Control vulnerability
Trending: 5
MEDIUMCVE-2026-57347EXP
WordPress Hotel Booking Lite plugin <= 6.0.3 - Sensitive Data Exposure vulnerability
HIGHCVE-2026-57644EXP
WordPress Restaurant Menu by MotoPress plugin <= 2.4.10 - SQL Injection vulnerability
MEDIUMCVE-2025-63078
WordPress Restaurant Menu by MotoPress plugin <= 2.4.11 - Broken Access Control vulnerability

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 1, 2026
Discovered by ZDM
Jul 1, 2026
Actively Exploited
Jul 1, 2026
Updated: severity, activelyExploited
Jul 1, 2026

Version History

v2
Last enriched 53d ago
v2Tier C53d ago

Updated severity to CRITICAL and marked the vulnerability as actively exploited.

severityactivelyExploited
via VulDB
v153d ago

Initial creation