What the vulnerability does
01Description
Missing Authorization vulnerability in magepeopleteam Booking and Rental Manager booking-and-rental-manager-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Booking and Rental Manager: from n/a through <= 2.6.0.
Explanation of Vulnerability in Simple Terms
02Summary
The Booking and Rental Manager plugin for WordPress contains an authorization flaw that allows authenticated users with low privileges to read sensitive data they should not access. An attacker with a standard user account can retrieve confidential information by making direct requests to the plugin. This affects all versions up to and including 2.6.0.
What an attacker can do
03Attacker Capabilities
Read sensitive data belonging to other users or the site without proper authorization.
Potential impact on your site
04Site Impact
Customer data, booking details, or other confidential information may be exposed to unauthorized users with site accounts.
Conditions required to exploit
05Prerequisites
Attacker must have a low-privilege user account (e.g., customer or subscriber role) on the site.
Key dates
06Disclosure timeline
March 25, 2026
CVE published
April 28, 2026
Record updated