CVE-2026-78258: WordPress Booking and Rental Manager plugin <= 2.7.5 - Broken Access Control vulnerability
Published Aug 24, 2026
·Updated
Unauthenticated Broken Access Control in Booking and Rental Manager <= 2.7.5 versions.
Affected Software
1 affected component
WordPress Booking and Rental Manager<=2.7.5
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Booking and Rental Managerto a version that resolves this vulnerability.Fixed in 2.7.6
Event History
Aug 24, 2026
CVE Published
via MITRE·11:39 AM
Data Sourced
via MITRE·11:39 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·12:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
An unauthenticated remote attacker can exploit the broken access control issue. No account or user interaction is required.
2
What security impact is reported?
The reported impact is limited to confidentiality: attackers may obtain some information. No integrity or availability impact is indicated.
3
Which installations are affected?
WordPress sites using Booking and Rental Manager version 2.7.5 or earlier are affected according to the available data.