Executive brief
The OwnerRez API WordPress plugin, used to manage property rental operations, contains an access control vulnerability that allows subscribers (lower-privilege users) to access pages and perform actions restricted to higher-privilege roles. An attacker with a subscriber account could view or manipulate data belonging to other properties or users, compromising operational security and customer data confidentiality.
Technical details
The vulnerability is a broken access control issue in the OwnerRez API WordPress plugin versions 1.2.6 and earlier. The root cause is insufficient authorization checks on API endpoints and WordPress admin pages, allowing authenticated subscribers to bypass role-based access controls and access or modify resources they should not be permitted to interact with. The attack requires a valid subscriber account (low privilege). An attacker can enumerate and access other users' property data, booking information, or administrative settings. The vulnerability was patched in version 1.3.0.
Affected products
- OwnerRez, Inc OwnerRez API <= 1.2.6
Timeline
- 2026-08-31: disclosed
- 2026-08-31: patched: Version 1.3.0 released
- 2026-08-21: other: Reported by JunHee CHO