Description
Missing Authorization vulnerability in designthemes DesignThemes Booking Manager designthemes-booking-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects DesignThemes Booking Manager: from n/a through <= 2.0.
Published: 2026-03-05
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Access with the potential for privilege escalation
Action: Immediate Patch
AI Analysis

Impact

The vulnerability in the DesignThemes Booking Manager WordPress plugin arises from a missing authorization check that permits users to bypass intended access controls. This broken access control flaw could enable an attacker, once authenticated or even unauthenticated, to perform privileged actions such as creating, modifying, or deleting bookings, accessing sensitive booking data, or altering administrative settings. The weakness is categorized under CWE-862, highlighting a failure to properly enforce authorization safeguards.

Affected Systems

WordPress installations that have the DesignThemes Booking Manager plugin version 2.0 or earlier are affected. The plugin is available for the standard WordPress environment and is distributed under the designthemes:DesignThemes Booking Manager CNA reference. No additional product versions are listed as impacted beyond the 2.0 or earlier threshold.

Risk and Exploitability

The CVSS score of 7.5 classifies the issue as high severity, indicating significant potential impact. The EPSS score of less than 1% suggests that, at present, the probability of exploitation is low, and the vulnerability is not reported in the CISA KEV catalog. The most likely attack vector is a web-based interaction within a WordPress site where the plugin’s functionality is exposed, though the description does not detail prerequisites such as user roles, making the exploitable conditions uncertain. Given the lack of disclosed proof‑of‑concept exploits, the risk remains theoretical but notable for sites that rely on the plugin for booking management.

Generated by OpenCVE AI on April 16, 2026 at 05:09 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Verify whether the plugin vendor has released an official update that addresses the access control flaw and apply it to the site.
  • Limit access to the plugin’s administrative functions to users with the administrator role or a trusted, custom user role that requires it.
  • If the plugin is not essential to the site’s functionality, consider deactivating or uninstalling it to remove the vulnerable code path.

Generated by OpenCVE AI on April 16, 2026 at 05:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 09 Mar 2026 13:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 06 Mar 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Designthemes
Designthemes designthemes Booking Manager
Wordpress
Wordpress wordpress
Vendors & Products Designthemes
Designthemes designthemes Booking Manager
Wordpress
Wordpress wordpress

Thu, 05 Mar 2026 06:15:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in designthemes DesignThemes Booking Manager designthemes-booking-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects DesignThemes Booking Manager: from n/a through <= 2.0.
Title WordPress DesignThemes Booking Manager plugin <= 2.0 - Broken Access Control vulnerability
Weaknesses CWE-862
References

Subscriptions

Designthemes Designthemes Booking Manager
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:15:03.136Z

Reserved: 2026-02-19T09:52:03.312Z

Link: CVE-2026-27388

cve-icon Vulnrichment

Updated: 2026-03-09T12:29:27.644Z

cve-icon NVD

Status : Deferred

Published: 2026-03-05T06:16:28.287

Modified: 2026-04-22T21:26:58.303

Link: CVE-2026-27388

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-16T05:15:25Z

Weaknesses