Unauthenticated Broken Access Control in Booking and Rental Manager by WordPress
CVE-2026-57660
5.3MEDIUM
What is CVE-2026-57660?
The Booking and Rental Manager plugin for WordPress allows unauthenticated users to bypass security measures, resulting in unauthorized access to sensitive functionalities. This vulnerability affects versions 2.7.1 and earlier, enabling potential exploitation through poorly enforced access restrictions.
Affected Version(s)
Booking and Rental Manager <= 2.7.1