Junglewise Threat Intelligence

CVE-2026-59532: MagePeople Booking and Rental Manager price manipulation

CVE-2026-59532 · Severity: high · CVSS 7.5 · Published 2026-07-27

Vendors: MagePeople Team.

Executive brief

The Booking and Rental Manager plugin for WooCommerce is vulnerable to a price manipulation flaw. This component is used by online stores to manage reservations and equipment rentals. An unauthenticated attacker can exploit this to modify prices during the booking process, potentially allowing them to purchase services or rent items at unauthorized rates, leading to financial loss for the business.

Technical details

The Booking and Rental Manager for WooCommerce plugin (versions 2.7.2 and below) contains a price manipulation vulnerability classified as Improper Validation of Specified Quantity in Input (CWE-1284). The flaw allows a remote, unauthenticated attacker to submit crafted requests that alter the intended price or quantity of a booking. This occurs because the plugin fails to properly validate or sanitize input fields related to the transaction amount or item count before processing the WooCommerce checkout. An attacker can exploit this to bypass intended pricing logic. The issue is resolved in version 2.7.3.

Affected products

  • MagePeople Team Booking and Rental Manager for WooCommerce <= 2.7.2

Timeline

  • 2026-05-08: disclosed: Reported by researcher dodoh4t
  • 2026-07-23: advisory: Patchstack published advisory
  • 2026-07-27: advisory: NVD published CVE record
  • 2026-07-27: patched: Version 2.7.3 released to address the vulnerability

References