CVE-2024-2749: VikBooking < 1.6.8 - Broken Access Control
The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.6.8's access control mechanism fails to properly restrict access to its settings, permitting any users that can access a menu to manipulate requests and perform unauthorized actions such as editing, renaming or deleting (categories for example) despite initial settings prohibiting such access. This vulnerability resembles broken access control, enabling unauthorized users to modify critical VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.6.8 configurations.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-2749?
CVE-2024-2749 has been rated as high severity due to improper access control in the VikBooking plugin.
How do I fix CVE-2024-2749?
To fix CVE-2024-2749, you should update the VikBooking Hotel Booking Engine & PMS plugin to version 1.6.8 or later.
Who is affected by CVE-2024-2749?
CVE-2024-2749 affects users of the VikBooking Hotel Booking Engine & PMS WordPress plugin prior to version 1.6.8.
What actions can unauthorized users perform due to CVE-2024-2749?
Unauthorized users can manipulate requests to edit, rename, or delete settings in the VikBooking plugin due to CVE-2024-2749.
What is the impact of CVE-2024-2749 on website security?
CVE-2024-2749 compromises website security by allowing unauthorized actions, which could lead to potential data breaches.