Junglewise Threat Intelligence

CVE-2026-57404: MagePeople Booking and Rental Manager missing authorization

CVE-2026-57404 · Severity: medium · CVSS 6.5 · Published 2026-07-13

Vendors: Magepeople inc..

Executive brief

The Booking and Rental Manager plugin for WooCommerce, which allows businesses to manage reservations and rentals on their websites, contains a security flaw in its access control settings. This vulnerability could allow unauthorized individuals to perform actions that should be restricted to administrators or specific staff members. Exploiting this could lead to unauthorized changes to booking data or disruptions to the rental service.

Technical details

A Broken Access Control (Missing Authorization) vulnerability exists in the MagePeople Booking and Rental Manager for WooCommerce plugin through version 2.6.9. The flaw stems from a failure to properly validate authorization or authentication tokens in certain functions, allowing unauthenticated remote attackers to execute actions that should require higher privileges. According to the CVSS vector, the attack is low complexity and requires no user interaction, potentially allowing an attacker to modify data or impact service availability. The issue is addressed in version 2.7.0.

Affected products

  • MagePeople Inc. Booking and Rental Manager for WooCommerce <= 2.6.9

Timeline

  • 2026-04-29: disclosed: Reported by hhhai to Patchstack
  • 2026-07-08: advisory: Patchstack advisory published
  • 2026-07-13: advisory: NVD published date
  • patched: Fixed in version 2.7.0

References