CVE-2026-78257: WordPress Booking and Rental Manager plugin <= 2.7.5 - PHP Object Injection vulnerability
Published Aug 27, 2026
·Updated
Contributor PHP Object Injection in Booking and Rental Manager <= 2.7.5 versions.
Affected Software
1 affected component
WordPress Booking and Rental Manager<=2.7.5
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Booking and Rental Manager pluginto a version that resolves this vulnerability.Fixed in 2.7.6
Event History
Aug 27, 2026
CVE Published
via MITRE·08:59 AM
Data Sourced
via MITRE·08:59 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·10:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The vulnerability requires Contributor-level access. It can be exploited remotely without user interaction once that level of WordPress access is available.
2
What is the potential impact if exploitation succeeds?
Successful exploitation can affect confidentiality, integrity, and availability at a high level. The reported severity is High, with a CVSS score of 8.8.
3
Which plugin versions are affected?
Booking and Rental Manager versions 2.7.5 and earlier are affected by the reported PHP object injection issue.