What the vulnerability does
01Description
Deserialization of Untrusted Data vulnerability in magepeopleteam Booking and Rental Manager booking-and-rental-manager-for-woocommerce allows Object Injection.This issue affects Booking and Rental Manager: from n/a through <= 2.2.6.
Explanation of Vulnerability in Simple Terms
02Summary
The Booking and Rental Manager plugin for WordPress contains a deserialization vulnerability in versions up to 2.2.6. An authenticated attacker with low privileges can send a specially crafted request to deserialize untrusted data, leading to arbitrary code execution on the site. This allows complete compromise of the WordPress installation, including data theft and site takeover.
What an attacker can do
03Attacker Capabilities
Run arbitrary PHP code on the site and fully compromise it.
Potential impact on your site
04Site Impact
Any user with low-privilege access can take over the site, steal data, or inject malware.
Conditions required to exploit
05Prerequisites
Attacker must have a low-privilege user account (e.g., subscriber or contributor role).
Key dates
06Disclosure timeline
March 15, 2025
CVE published
April 28, 2026
Record updated