{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/hotel-booking--6.2.4/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:motopress:hotel_booking:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-90650"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Hotel Booking (\u003c= 6.2.4)"],"_cs_severities":["high"],"_cs_tags":["web-application","xss","wordpress","plugin-vulnerability"],"_cs_type":"advisory","_cs_vendors":["MotoPress"],"content_html":"\u003cp\u003eThe MotoPress Hotel Booking plugin for WordPress, in versions up to and including 6.2.4, contains a vulnerability that allows unauthenticated attackers to execute Stored Cross-Site Scripting (XSS). The vulnerability exists within the premium Stripe gateway integration's webhook handler, located in \u003ccode\u003ewebhook-listener.php\u003c/code\u003e. Because the plugin defaults to having no Stripe signing secret configured, the webhook handler fails to cryptographically verify incoming Stripe webhook events. An attacker can submit a forged webhook, such as a crafted 'refund.created' event, containing a malicious payload in the 'id' field of the event object. This payload is stored directly in the plugin's payment logs without sanitization. The vulnerability is triggered when an administrator subsequently accesses the payment logs through the WordPress dashboard, causing the stored script to execute within the administrator's session context. This vulnerability presents a significant risk to site administration, potentially leading to unauthorized actions or credential theft.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies a target WordPress site using the MotoPress Hotel Booking plugin with the premium Stripe integration enabled.\u003c/li\u003e\n\u003cli\u003eAttacker obtains a valid Stripe PaymentIntent ID associated with the target's legitimate payment records.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a forged Stripe webhook request, setting the 'id' field of the event object to a malicious JavaScript payload.\u003c/li\u003e\n\u003cli\u003eAttacker sends the forged POST request to the plugin's webhook endpoint (typically accessible via public URL).\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003ewebhook-listener.php\u003c/code\u003e script receives the POST request and, due to the default absence of a signing secret, fails to verify the signature.\u003c/li\u003e\n\u003cli\u003eThe plugin extracts the malicious 'id' value from the request and writes it to the database as part of the payment log.\u003c/li\u003e\n\u003cli\u003eA site administrator logs into the WordPress dashboard and navigates to the payment history page.\u003c/li\u003e\n\u003cli\u003eThe application displays the payment log, rendering the unsanitized malicious payload in the administrator's browser, triggering script execution.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to execute arbitrary JavaScript in the context of an administrator's browser session. This can result in unauthorized administrative actions, site configuration changes, theft of session tokens, or further compromise of the WordPress environment. The vulnerability impacts all users of the MotoPress Hotel Booking premium plugin running versions 6.2.4 and earlier.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the update of the MotoPress Hotel Booking plugin to version 6.2.5 or later to resolve the input validation and signature verification flaws associated with CVE-2026-90650. Ensure that a unique and complex Stripe signing secret is generated and configured in the plugin settings to enforce cryptographic signature verification for all incoming webhooks. Monitor web server logs for high volumes of POST requests to the plugin's webhook endpoint originating from non-Stripe IP addresses.\u003c/p\u003e\n","date_modified":"2026-09-15T15:41:13Z","date_published":"2026-09-15T15:41:13Z","id":"https://feed.craftedsignal.io/briefs/2026-09-motopress-xss/","summary":"The MotoPress Hotel Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Stripe webhook listener due to missing signature verification and improper output sanitization.","title":"Stored Cross-Site Scripting in MotoPress Hotel Booking Plugin","url":"https://feed.craftedsignal.io/briefs/2026-09-motopress-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - Hotel Booking (\u003c= 6.2.4)","version":"https://jsonfeed.org/version/1.1"}