findById of the file /motopress/appointment/v1/bookings of the component REST Endpoint. Performing a manipulation of the argument payment_details.booking_id results in authorization bypass.
This vulnerability was named CVE-2026-9180. The attack may be initiated remotely. There is no available exploit.
Intelligence View
SOCIAL SHARE CARD GENERATOR