CVE-2025-39390: WordPress Booking and Rental Manager plugin <= 2.3.6 - Broken Access Control vulnerability
Missing Authorization vulnerability in magepeopleteam Booking and Rental Manager allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Booking and Rental Manager: from n/a through 2.3.8.
Other sources
Missing Authorization vulnerability in magepeopleteam Booking and Rental Manager booking-and-rental-manager-for-woocommerce allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Booking and Rental Manager: from n/a through <= 2.3.6.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-39390?
CVE-2025-39390 is classified as a high severity vulnerability due to its potential to allow unauthorized access to sensitive functionality.
How do I fix CVE-2025-39390?
To fix CVE-2025-39390, update the Booking and Rental Manager plugin to version 2.3.9 or later, which addresses the missing authorization vulnerability.
What software is affected by CVE-2025-39390?
CVE-2025-39390 affects the Magepeople Booking and Rental Manager and WordPress Booking and Rental Manager versions up to and including 2.3.8.
What kind of attack can exploit CVE-2025-39390?
An attacker could exploit CVE-2025-39390 to perform unauthorized actions by bypassing Access Control Lists (ACLs) due to misconfigured permissions.
Is there a workaround for CVE-2025-39390?
As a temporary workaround for CVE-2025-39390, disable the affected functionalities until the plugin can be updated to a secure version.