Impact
The Booking and Rental Manager plugin for WordPress with versions up to 2.7.6 contains a broken access control flaw that allows users with the standard subscriber role to perform actions normally reserved for higher‑privilege accounts, such as creating, modifying, or deleting bookings and rentals. This flaw is rooted in a failure to correctly check the user's capabilities before executing booking‑related requests, as identified by CWE‑862.
Affected Systems
WordPress sites that use the magepeopleteam Booking and Rental Manager plugin version 2.7.6 or earlier, typically when installed on a WooCommerce‑based store. The vulnerability affects the plugin’s booking management endpoints that are accessible to all logged‑in users, regardless of role.
Risk and Exploitability
The flaw has a CVSS score of 6.5, indicating moderate severity. No EPSS score is available, and the vulnerability is not currently listed in the CISA KEV catalog. An attacker must first authenticate to the site as a subscriber; once authenticated, the lack of proper authorization checks allows the attacker to exploit the vulnerability. The exploitation path is straightforward and does not require additional conditions, making it a likely target for attackers who can gain a low‑privilege account.
OpenCVE Enrichment