CVE-2025-64266: WordPress Booking and Rental Manager plugin <= 2.5.4 - PHP Object Injection vulnerability
Deserialization of Untrusted Data vulnerability in magepeopleteam Booking and Rental Manager booking-and-rental-manager-for-woocommerce allows Object Injection.This issue affects Booking and Rental Manager: from n/a through <= 2.5.4.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-64266?
CVE-2025-64266 has been classified as a high severity vulnerability due to its potential for object injection and deserialization of untrusted data.
How do I fix CVE-2025-64266?
To mitigate CVE-2025-64266, upgrade the Booking and Rental Manager plugin to version 2.5.5 or higher.
What are the risks of not addressing CVE-2025-64266?
Failing to address CVE-2025-64266 could lead to unauthorized access, data manipulation, or remote code execution on your site.
Which versions of Booking and Rental Manager are affected by CVE-2025-64266?
CVE-2025-64266 affects Booking and Rental Manager versions up to and including 2.5.4.
What is Object Injection as described in CVE-2025-64266?
Object Injection is a vulnerability that allows an attacker to inject malicious objects into a program, potentially manipulating its execution and data.