Executive brief
The Booking and Rental Manager plugin for WordPress, which handles online reservations and rental services for WooCommerce stores, contains a security flaw. An unauthenticated attacker can bypass access controls to perform actions that should be restricted to authorized users. This could allow unauthorized changes to booking data or system settings, potentially disrupting business operations.
Technical details
The Booking and Rental Manager for WooCommerce plugin (versions <= 2.7.1) is vulnerable to broken access control due to missing authorization checks (CWE-862). A remote, unauthenticated attacker can exploit this flaw to execute functions or modify data that should require higher privileges. The vulnerability stems from a failure to validate user permissions or implement proper nonce checks in affected components. An exploit could lead to unauthorized integrity changes, though it is not reported to impact data confidentiality or service availability. A fix is available in version 2.7.2.
Affected products
- Magepeople inc. Booking and Rental Manager for WooCommerce <= 2.7.1
Timeline
- 2026-06-03: other: Reported by researcher Averon Averenkov
- 2026-06-26: advisory: Published by Patchstack and NVD
- 2026-06-26: patched: Version 2.7.2 released to address the vulnerability