CVE-2025-26921: WordPress Booking and Rental Manager Plugin <= 2.2.6 - PHP Object Injection vulnerability
Published Mar 15, 2025
·Updated
Deserialization of Untrusted Data vulnerability in magepeopleteam Booking and Rental Manager booking-and-rental-manager-for-woocommerce allows Object Injection.This issue affects Booking and Rental Manager: from n/a through <= 2.2.6.
Affected Software
1 affected component
MagePeopleTeam Booking and Rental Manager for WooCommerce<=2.2.6
Remediation
Information
Update the WordPress Booking and Rental Manager wordpress plugin to the latest available version (at least 2.2.7).
Event History
Mar 15, 2025
CVE Published
via MITRE·09:57 PM
Data Sourced
via MITRE·09:57 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-26921?
The severity of CVE-2025-26921 is rated as high due to the potential for object injection and deserialization of untrusted data.
2
How do I fix CVE-2025-26921?
To fix CVE-2025-26921, update the Booking and Rental Manager to version 2.2.7 or later.
3
What versions are affected by CVE-2025-26921?
CVE-2025-26921 affects Magepeopleteam Booking and Rental Manager versions from n/a up to 2.2.6.
4
What type of vulnerability is CVE-2025-26921?
CVE-2025-26921 is classified as a Deserialization of Untrusted Data vulnerability.
5
Which products are impacted by CVE-2025-26921?
CVE-2025-26921 impacts the Magepeopleteam Booking and Rental Manager and the WordPress Booking and Rental Manager Plugin.