Impact
The Booking and Rental Manager plugin for WordPress contains an unauthenticated flaw that allows an attacker to change booking or rental prices before a transaction is finalized, leading to potential financial loss or fraudulent charges. The weakness is classified as CWE‑1284, indicating that user input is incorporated insecurely into the pricing logic, bypassing proper validation or authorization controls.
Affected Systems
This vulnerability affects WordPress sites that have installed the Booking and Rental Manager plugin from the Magepeopleteam vendor, specifically any version through 2.7.2. Updating the plugin to version 2.7.3 or later removes the flaw.
Risk and Exploitability
The CVSS score of 7.5 signals a high severity risk, while the EPSS score of <1% suggests a low overall exploitation probability at present. However, because the flaw is unauthenticated, anyone who can access the booking flow can potentially manipulate prices, making the vulnerability exploitable. The absence from the CISA KEV catalog indicates no publicly documented exploits, but the lack of authentication control raises the likelihood of attack if the site is reachable.
OpenCVE Enrichment