Executive brief
The Booking Manager WordPress plugin fails to verify user ownership before allowing modifications to booking settings, enabling any subscriber-level user to alter settings for other accounts, including administrators. An attacker with a low-privilege account could modify an administrator's booking configuration or create unauthorized settings on arbitrary user accounts, potentially leading to privilege escalation or service disruption.
Technical details
An insecure direct object reference (IDOR) vulnerability in the plugin's per-user settings modification endpoint allows authenticated users with subscriber-level access or higher to modify plugin settings for any user account without authorization checks. The vulnerable functionality does not validate that the requesting user matches the target user before applying changes. Exploitation requires only valid WordPress authentication at subscriber level or above.
Affected products
- Booking Manager Booking Manager before 2.1.21
Timeline
- 2026-09-21: disclosed
- 2026-09-21: patched: Fixed in version 2.1.21