Description
The Booking Manager WordPress plugin before 2.1.21 does not verify that a request to modify a user's Booking Manager WordPress plugin before 2.1.21-specific settings targets the requesting user's own account, allowing any authenticated user with subscriber-level access and above to create or overwrite the Booking Manager WordPress plugin before 2.1.21's per-user settings on arbitrary users, including administrators.
Published: 2026-09-23
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation via IDOR that enables modification of other users' Booking Manager settings
Action: Update Plugin
AI Analysis

Impact

The vulnerability is an Insecure Direct Object Reference that allows any authenticated user with subscriber-level role or higher to modify the Booking Manager per‑user settings of other accounts. By crafting a request targeting another user's ID, an attacker can overwrite the target's plugin configuration, potentially redirect bookings or disrupt the plugin’s normal operation, thereby compromising the integrity of booking data.

Affected Systems

The affected product is the Booking Manager WordPress plugin for any site that installs the plugin version prior to 2.1.21. The vulnerability exists in all builds before that release; no specific patch version beyond 2.1.21 is documented.

Risk and Exploitability

The CVSS score of 4.3 indicates a medium severity issue. The EPSS score of less than 1% suggests a low probability of exploitation. The vulnerability is not listed in CISA's KEV catalog. Attackers must first authenticate to WordPress with a subscriber role or higher. The IDOR flaw allows them to send an HTTP request to the plugin’s settings endpoint with a target user ID. Once successful, any per‑user configuration can be overwritten.

Generated by OpenCVE AI on September 23, 2026 at 15:12 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Booking Manager plugin to version 2.1.21 or later, where the IDOR check has been fixed.
  • Reduce the number of users with subscriber or higher roles, or disable the affected plugin for accounts that do not need access.
  • Monitor WordPress administrative logs for unexpected changes to plugin metadata and restrict direct access to the plugin’s configuration endpoint.

Generated by OpenCVE AI on September 23, 2026 at 15:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
Description The Booking Manager WordPress plugin before 2.1.21 does not verify that a request to modify a user's Booking Manager WordPress plugin before 2.1.21-specific settings targets the requesting user's own account, allowing any authenticated user with subscriber-level access and above to create or overwrite the Booking Manager WordPress plugin before 2.1.21's per-user settings on arbitrary users, including administrators.
Title Booking Manager < 2.1.21 - Subscriber+ Arbitrary User Plugin Meta Modification via IDOR
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-23T10:52:13.061Z

Reserved: 2026-09-14T17:11:18.498Z

Link: CVE-2026-91025

cve-icon Vulnrichment

Updated: 2026-09-23T10:33:23.330Z

cve-icon NVD

Status : Received

Published: 2026-09-23T06:17:05.523

Modified: 2026-09-23T11:17:17.350

Link: CVE-2026-91025

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-23T15:15:05Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key