Junglewise Threat Intelligence

CVE-2026-13454: MotoPress Appointment Booking SQL injection in s parameter

CVE-2026-13454 · Severity: medium · CVSS 6.5 · Published 2026-07-01

Technologies: MotoPress Appointment Booking. Vendors: MotoPress.

Executive brief

The MotoPress Appointment Booking plugin for WordPress, which manages service scheduling and staff appointments, contains a security flaw. An authorized staff member could exploit this vulnerability to gain unauthorized access to the website's database. This could lead to the theft of sensitive business information, customer data, or administrative credentials.

Technical details

A SQL injection vulnerability exists in the ManageBookingsPage.php component of the MotoPress Appointment Booking plugin due to insufficient escaping of the 's' parameter and a lack of SQL query preparation. Authenticated attackers with the 'mpa_appointment_employee' custom role can inject malicious SQL commands into existing queries. This flaw enables the extraction of sensitive data from the WordPress database. The issue affects all versions up to and including 2.4.5; users should update to a patched version if available.

Affected products

  • MotoPress Appointment Booking Up to and including 2.4.5

Timeline

  • 2026-07-01: advisory: Vulnerability published by Wordfence/NVD

References

Related threats