Impact
A missing authorization flaw in the magepeopleteam Booking and Rental Manager WordPress plugin allows an attacker to access and potentially modify booking and rental related data without proper authentication. The vulnerability specifically permits operations that should be restricted to privileged users, exposing sensitive information and enabling unauthorized changes to bookings, orders, or rental listings. The weakness is categorized as a Missing Authorization flaw (CWE‑862).
Affected Systems
The flaw affects the Booking and Rental Manager plugin for WordPress released by magepeopleteam. Any installation of the plugin at version 2.6.9 or earlier is vulnerable; newer releases are not mentioned as affected.
Risk and Exploitability
The CVSS score of 6.5 indicates a medium severity risk, while the less than 1% suggests that exploits are currently uncommon. The vulnerability is not listed in the CISA KEV catalog, meaning no publicly known large‑scale exploits have been observed yet. Likely attack vectors involve remote HTTP requests to the plugin’s administrative or REST API endpoints, and the flaw can be triggered without special prerequisites beyond sending the appropriate request as an unauthenticated user.
OpenCVE Enrichment