Junglewise Threat Intelligence

CVE-2026-78258: WordPress Booking and Rental Manager broken access control

CVE-2026-78258 · Severity: medium · CVSS 5.3 · Published 2026-08-24

Executive brief

Booking and Rental Manager is a popular WordPress plugin for managing rental reservations and bookings on e-commerce sites. An unauthenticated attacker can bypass access controls to view or modify data they should not have permission to access, potentially exposing customer booking information and reservation details.

Technical details

The Booking and Rental Manager WordPress plugin through version 2.7.5 contains a broken access control vulnerability classified as OWASP A01:2021. The vulnerability allows unauthenticated attackers to access restricted pages or perform unauthorized actions without proper permission validation. Attack vectors are network-accessible and require no authentication or user interaction. The vulnerability was patched in version 2.7.6; affected installations should update immediately to mitigate unauthorized data access to customer bookings and rental information.

Affected products

  • Magepeople Booking and Rental Manager <= 2.7.5

Timeline

  • 2026-01-21: disclosed: Reported by Bao - BlueRock
  • 2026-08-24: advisory: Published by Patchstack
  • 2026-08-24: patched: Version 2.7.6 released

References

Related threats