Executive brief
WP Rentals is a popular WordPress rental management theme used to manage property listings and bookings. An authorization bypass vulnerability allows attackers with subscriber-level access to view and potentially modify rental properties and data belonging to other users by manipulating object identifiers in URLs, compromising data privacy and integrity.
Technical details
This is an Insecure Direct Object References (IDOR) vulnerability—a broken access control flaw where object identifiers (IDs) in URLs are not properly validated against user permissions. An authenticated subscriber can change rental object IDs in the URL to access or manipulate other users' rental properties and associated data. The vulnerability requires an authenticated account (subscriber level or higher) but no additional interaction. Exploitation allows data exposure and unauthorized modification of other users' rental records. The vulnerability was patched in version 3.16.0.
Affected products
- sc Internet Vivoo WP Rentals before 3.16.0
Timeline
- 2025-10-15: disclosed: Vulnerability reported by Rafie Muhammad
- 2026-09-04: advisory: Published by Patchstack and disclosed via NVD
- 2026-09-04: patched: Patched in version 3.16.0