Description
Missing Authorization vulnerability in magepeopleteam Booking and Rental Manager booking-and-rental-manager-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Booking and Rental Manager: from n/a through <= 2.6.9.
Published: 2026-07-13
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A missing authorization flaw in the magepeopleteam Booking and Rental Manager WordPress plugin allows an attacker to access and potentially modify booking and rental related data without proper authentication. The vulnerability specifically permits operations that should be restricted to privileged users, exposing sensitive information and enabling unauthorized changes to bookings, orders, or rental listings. The weakness is categorized as a Missing Authorization flaw (CWE‑862).

Affected Systems

The flaw affects the Booking and Rental Manager plugin for WordPress released by magepeopleteam. Any installation of the plugin at version 2.6.9 or earlier is vulnerable; newer releases are not mentioned as affected.

Risk and Exploitability

The CVSS score of 6.5 indicates a medium severity risk, while the less than 1% suggests that exploits are currently uncommon. The vulnerability is not listed in the CISA KEV catalog, meaning no publicly known large‑scale exploits have been observed yet. Likely attack vectors involve remote HTTP requests to the plugin’s administrative or REST API endpoints, and the flaw can be triggered without special prerequisites beyond sending the appropriate request as an unauthenticated user.

Generated by OpenCVE AI on July 31, 2026 at 11:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Booking and Rental Manager plugin to any version newer than 2.6.9 to remove the missing authorization flaw.
  • If an upgrade cannot be performed immediately, disable all booking‑related administrative pages or REST endpoints and restrict access to the plugin’s functionality to users with the Administrator role.
  • Review and enforce proper role‑, ensuring that only authorized administrators can invoke booking and rental management actions.

Generated by OpenCVE AI on July 31, 2026 at 11:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in magepeopleteam Booking and Rental Manager booking-and-rental-manager-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Booking and Rental Manager: from n/a through <= 2.6.9.
Title WordPress Booking and Rental Manager plugin <= 2.6.9 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-13T16:07:52.647Z

Reserved: 2026-06-24T12:46:27.804Z

Link: CVE-2026-57404

cve-icon Vulnrichment

Updated: 2026-07-13T16:02:24.157Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T12:00:05Z

Weaknesses