Access Control Vulnerability in Booking and Rental Manager by MagePeopleTeam
CVE-2026-57404
6.5MEDIUM
What is CVE-2026-57404?
A significant Missing Authorization vulnerability affects the Booking and Rental Manager for WooCommerce by MagePeopleTeam. This vulnerability arises from incorrectly configured access control security levels, allowing unauthorized access to the booking and reservation functionalities. Specifically, versions up to 2.6.9 may expose sensitive user actions and data to malicious actors, making it imperative for users to address this security issue to protect their online booking systems.
Affected Version(s)
Booking and Rental Manager 0 <= 2.6.9