CVE-2026-81762: WordPress Booking and Rental Manager plugin <= 2.7.6 - Broken Access Control vulnerability
Published Aug 31, 2026
·Updated
Subscriber Broken Access Control in Booking and Rental Manager <= 2.7.6 versions.
Affected Software
1 affected component
wordpress/booking-and-rental-manager<=2.7.6
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Booking and Rental Manager pluginto a version that resolves this vulnerability.Fixed in 2.7.7
Event History
Aug 31, 2026
CVE Published
via MITRE·08:30 PM
Data Sourced
via MITRE·08:30 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
An attacker needs a Subscriber-level account on a WordPress site using the affected plugin. The attack can be performed over the network and does not require user interaction.
2
What is the likely security impact?
The vulnerability has high integrity impact, meaning an authenticated Subscriber may be able to make unauthorized changes. No confidentiality or availability impact is indicated by the supplied CVSS vector.
3
Which installations are in scope?
WordPress sites using Booking and Rental Manager version 2.7.6 or earlier are affected according to the provided data.