Access Control Flaw in DesignThemes Booking Manager by DesignThemes
CVE-2026-27388
7.5HIGH
What is CVE-2026-27388?
A missing authorization vulnerability exists in the DesignThemes Booking Manager, enabling attackers to exploit incorrectly configured access control security levels. This flaw permits unauthorized users to gain access to functionalities that should be restricted, potentially compromising sensitive data and allowing manipulation of booking records. The issue is present in all versions up to and including 2.0, underscoring the importance of maintaining proper access control to safeguard application integrity.
Affected Version(s)
DesignThemes Booking Manager 0 <= 2.0