Junglewise Threat Intelligence

CVE-2026-81762: Booking and Rental Manager broken access control in subscriber operations

CVE-2026-81762 · Severity: medium · CVSS 6.5 · Published 2026-08-31

Executive brief

Booking and Rental Manager is a WordPress plugin that allows customers to manage rental bookings on WooCommerce-powered websites. The plugin contains a broken access control vulnerability that allows subscriber-level users to view and perform actions they shouldn't have permission for, such as accessing other customers' booking data. This could expose sensitive customer information and allow unauthorized modifications to bookings.

Technical details

The vulnerability is a broken access control flaw (OWASP A1) in Booking and Rental Manager versions 2.7.6 and earlier. The issue allows users with subscriber-level privileges to bypass authorization checks and access resources or perform actions restricted to other users or roles. The vulnerability requires authentication (subscriber account) to exploit and is triggered through normal plugin operations. An attacker with a subscriber account can view other customers' booking data or manipulate bookings. The vulnerability was patched in version 2.7.7.

Affected products

  • Magepeople Booking and Rental Manager <= 2.7.6

Timeline

  • 2026-08-31: disclosed
  • 2026-08-31: patched: Version 2.7.7 resolves the vulnerability

References

Related threats