Authorization Bypass in Booking Manager Plugin by WordPress
CVE-2026-91025
Currently unrated
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 23 September 2026
Badges
๐พ Exploit Exists๐ก Public PoC
What is CVE-2026-91025?
The Booking Manager plugin for WordPress prior to version 2.1.21 contains an authorization bypass vulnerability. This flaw allows authenticated users with subscriber-level access and above to manipulate the Booking Manager's per-user settings of any user, including administrators. The plugin fails to ensure that requests to modify settings are restricted to the requesting user's own account, posing a significant security risk.
Affected Version(s)
Booking Manager 0 < 2.1.21
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.