Unauthenticated Access Control Flaw in Booking and Rental Manager by WordPress
CVE-2026-78258

5.3MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
24 August 2026

What is CVE-2026-78258?

The Booking and Rental Manager plugin for WordPress suffers from a vulnerability that allows unauthenticated users to exploit broken access controls. This issue affects versions up to 2.7.5, potentially allowing unauthorized users to gain access to restricted functionalities. Administrators should apply necessary updates and review access control measures to mitigate risks associated with this vulnerability.

Affected Version(s)

Booking and Rental Manager <= 2.7.5

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Bao - BlueRock | Patchstack Bug Bounty Program
.