CVE-2025-27011: WordPress Booking and Rental Manager plugin <= 2.2.8 - Local File Inclusion vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in magepeopleteam Booking and Rental Manager allows PHP Local File Inclusion. This issue affects Booking and Rental Manager: from n/a through 2.2.8.
Other sources
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in magepeopleteam Booking and Rental Manager booking-and-rental-manager-for-woocommerce allows PHP Local File Inclusion.This issue affects Booking and Rental Manager: from n/a through <= 2.2.8.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-27011?
CVE-2025-27011 is classified as a high severity vulnerability due to its potential for local file inclusion, which can lead to unauthorized access to sensitive files.
How do I fix CVE-2025-27011?
To fix CVE-2025-27011, update the Booking and Rental Manager plugin to version 2.2.9 or later, which addresses the local file inclusion vulnerability.
What are the potential impacts of CVE-2025-27011?
The potential impacts of CVE-2025-27011 include unauthorized access to sensitive files on the server, which can lead to data breaches.
Which versions of Booking and Rental Manager are affected by CVE-2025-27011?
CVE-2025-27011 affects all versions of Booking and Rental Manager up to and including version 2.2.8.
Is CVE-2025-27011 specific to any platform?
Yes, CVE-2025-27011 is specific to the Booking and Rental Manager plugin for both MagePeople and WordPress platforms.