Junglewise Threat Intelligence

CVE-2026-78257: Booking and Rental Manager PHP object injection

CVE-2026-78257 · Severity: high · CVSS 8.8 · Published 2026-08-27

Executive brief

Booking and Rental Manager is a popular WordPress plugin that enables rental and booking functionality for WooCommerce stores. A PHP object injection vulnerability in versions 2.7.5 and earlier allows authenticated contributors to execute arbitrary code on the server, potentially compromising the entire website and its customer data.

Technical details

The vulnerability is a PHP object injection flaw in Booking and Rental Manager versions 2.7.5 and earlier. It allows authenticated users with the Contributor role to inject malicious serialized objects, leading to arbitrary code execution on the server. The attack requires network access and valid WordPress credentials (Contributor privilege or higher). An attacker can instantiate arbitrary PHP classes and trigger dangerous methods, resulting in full remote code execution. The vulnerability was patched in version 2.7.6.

Affected products

  • Magepeople Booking and Rental Manager <= 2.7.5

Timeline

  • 2026-01-19: disclosed
  • 2026-08-25: patched: Version 2.7.6 released
  • 2026-08-27: advisory

References

Related threats