First published: Thu Apr 17 2025(Updated: )
Missing Authorization vulnerability in magepeopleteam Booking and Rental Manager allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Booking and Rental Manager: from n/a through 2.2.8.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Magepeople Booking & Rental Manager | <=2.2.8 | |
WordPress Booking and Rental Manager | <=2.2.8 |
Update the WordPress Booking and Rental Manager plugin to the latest available version (at least 2.2.9).
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-39457 is classified as a missing authorization vulnerability which can lead to unauthorized access to sensitive functionalities.
To fix CVE-2025-39457, upgrade the Booking and Rental Manager plugin to version 2.2.9 or later to ensure proper access control measures are in place.
CVE-2025-39457 affects all versions of Booking and Rental Manager from n/a up to and including 2.2.8.
CVE-2025-39457 is a broken access control vulnerability that results from incorrectly configured access control security levels.
Users of the Booking and Rental Manager and WordPress Booking and Rental Manager plugin versions up to 2.2.8 are impacted by CVE-2025-39457.