CVE-2025-69328: WordPress Booking and Rental Manager plugin <= 2.5.9 - PHP Object Injection vulnerability
Deserialization of Untrusted Data vulnerability in magepeopleteam Booking and Rental Manager booking-and-rental-manager-for-woocommerce allows Object Injection.This issue affects Booking and Rental Manager: from n/a through <= 2.5.9.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-69328?
CVE-2025-69328 has been identified as a critical severity vulnerability due to its potential for PHP Object Injection.
How do I fix CVE-2025-69328?
To mitigate CVE-2025-69328, update the Booking and Rental Manager plugin to version 2.6.0 or higher.
What does CVE-2025-69328 affect?
CVE-2025-69328 affects versions of the Booking and Rental Manager plugin for WordPress up to and including 2.5.9.
What is PHP Object Injection in the context of CVE-2025-69328?
PHP Object Injection in CVE-2025-69328 refers to the vulnerability allowing an attacker to inject untrusted serialized data into the application.
Who is responsible for the CVE-2025-69328 vulnerability?
The CVE-2025-69328 vulnerability has been identified in the Booking and Rental Manager plugin developed by magepeopleteam.