Description
Missing Authorization vulnerability in magepeopleteam Booking and Rental Manager booking-and-rental-manager-for-woocommerce allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Booking and Rental Manager: from n/a through <= 2.3.6.
Published: 2025-04-24
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A missing authorization check in the Booking and Rental Manager plugin for WooCommerce allows users to call functions that were not properly protected by access control lists. Because the plugin fails to verify the caller’s permissions when accessing certain operations, an attacker could invoke administrative features such as creating, editing, or deleting rental listings, reservations, or related data without authentication. This flaw does not lead to code execution or privilege escalation beyond the scope of the plugin’s functionality, but it compromises the confidentiality and integrity of booking data for sites using the affected version. The weakness corresponds to the vulnerability type Quantum of CWE-862, Broken Access Control.

Affected Systems

The issue affects WordPress sites using the Booking and Rental Manager plugin version 2.3.6 or older. The plugin is developed by MagepeopleTeam, and the vulnerable functionality is available to any authenticated user in the site’s administrative interface or, depending on the call, possibly to publicly accessible endpoints without proper checks. Site owners should verify whether they are running any version up to and including 2.3.6.

Risk and Exploitability

The CVSS score of 5.3 represents a moderate impact, suggesting that while the vulnerability can be abused to alter or delete booking data, it generally does not expose a system-wide compromise. The EPSS score of less than 1% indicates a very low likelihood of exploitation at present, and the vulnerability is not listed in the CISA KEV catalog, further supporting a lower threat profile for current deployment. Nevertheless, the flaw allows unauthenticated or improperly authenticated users to reach functionalities they should not access, which can be abused if combined with social engineering or other credential compromise methods. Site administrators should treat this as a necessary patch due to the risk of data tampering or loss.

Generated by OpenCVE AI on April 30, 2026 at 21:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Booking and Rental Manager plugin to the latest release that resolves the broken access control issue.
  • If an immediate update is not possible, restrict access to the plugin’s administrative pages by employing role‑based access controls in WordPress so that only trusted accounts can reach the affected endpoints.
  • Regularly audit the site’s booking and reservation logs for unauthorized activity, and apply stricter monitoring for any changes to listings or reservations that may indicate exploitation.

Generated by OpenCVE AI on April 30, 2026 at 21:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-12073 Missing Authorization vulnerability in magepeopleteam Booking and Rental Manager allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Booking and Rental Manager: from n/a through 2.3.8.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in magepeopleteam Booking and Rental Manager allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Booking and Rental Manager: from n/a through 2.3.8. Missing Authorization vulnerability in magepeopleteam Booking and Rental Manager booking-and-rental-manager-for-woocommerce allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Booking and Rental Manager: from n/a through <= 2.3.6.
Title WordPress Booking and Rental Manager plugin <= 2.3.8 - Broken Access Control vulnerability WordPress Booking and Rental Manager plugin <= 2.3.6 - Broken Access Control vulnerability
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Fri, 25 Apr 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 24 Apr 2025 16:15:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in magepeopleteam Booking and Rental Manager allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Booking and Rental Manager: from n/a through 2.3.8.
Title WordPress Booking and Rental Manager plugin <= 2.3.8 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:30.225Z

Reserved: 2025-04-16T06:22:42.846Z

Link: CVE-2025-39390

cve-icon Vulnrichment

Updated: 2025-04-24T19:56:24.171Z

cve-icon NVD

Status : Deferred

Published: 2025-04-24T16:15:32.330

Modified: 2026-04-23T15:29:27.883

Link: CVE-2025-39390

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T21:30:36Z

Weaknesses