← WordPress Vulnerabilities
WordPress security by component

Booking and Rental Manager

Booking and Rental Manager is a WordPress component with 15 published CVE records in this archive. The latest tracked vulnerability was published Jul 27, 2026; the highest CVE/CNA score is 8.8.

Plugin slug: booking-and-rental-manager-for-woocommerce

CVE-2026-59532: Booking and Rental Manager permits unauthenticated price manipulation

Booking and Rental Manager through 2.7.2 accepts attacker-controlled pricing input through an unauthenticated booking or rental flow without enforcing the server-authorized amount. An attacker can manipulate a transaction price. The Patchstack CNA record does not disclose the route, action, price parameter, validation function, affected product types or whether payment completion is required.

PublishedJul 27, 2026
Known safe version2.7.3
Safe version
Jul 27, 2026 CVE-2026-59532
Booking and Rental Manager permits unauthenticated price manipulation
Booking and Rental Manager through 2.7.2 accepts attacker-controlled pricing input through an unauthenticated booking or rental flow without enforcing the server-authorized amount. An attacker can manipulate a transaction price. The Patchstack CNA record does not disclose the route, action, price parameter, validation function, affected product types or whether payment completion is required.
2.7.3
CVE7.5
NVDPending
Jul 13, 2026 CVE-2026-57404
Booking and Rental Manager: A security weakness
Booking and Rental Manager is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 2.6.9.
2.7.0
CVE6.5
NVDPending
Jun 26, 2026 CVE-2026-57660
Booking and Rental Manager: A security weakness
Booking and Rental Manager is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 2.7.1.
2.7.2
CVE5.3
NVDPending
Mar 25, 2026 CVE-2026-23972
Booking and Rental Manager: A security weakness
Booking and Rental Manager is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 2.6.0.
2.6.1
CVE6.5
NVDPending
Feb 20, 2026 CVE-2025-69328
Booking and Rental Manager: Code execution
Booking and Rental Manager is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE8.8
NVDPending
Dec 18, 2025 CVE-2025-64266
Booking and Rental Manager: Code execution
Booking and Rental Manager is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE8.8
NVDPending
Nov 06, 2025 CVE-2025-49904
Booking and Rental Manager: Cross-site scripting
Booking and Rental Manager is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.1
NVDPending
Jun 02, 2025 CVE-2025-47585
Booking and Rental Manager: A security weakness
Booking and Rental Manager is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.5
NVDPending
Apr 24, 2025 CVE-2025-39390
Booking and Rental Manager: A security weakness
Booking and Rental Manager is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Apr 17, 2025 CVE-2025-39457
Booking and Rental Manager: A security weakness
Booking and Rental Manager is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Apr 15, 2025 CVE-2025-27011
Booking and Rental Manager: Filesystem traversal
Booking and Rental Manager is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE7.5
NVDPending
Mar 15, 2025 CVE-2025-26921
Booking and Rental Manager: Code execution
Booking and Rental Manager is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE8.8
NVDPending
Jan 31, 2025 CVE-2025-22720
Booking and Rental Manager: A security weakness
Booking and Rental Manager is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.8
NVDPending
Jan 11, 2025 CVE-2024-12412
Rental and Booking Manager for Bike, Car, Dress, Resort with WooCommerce Integration – WpRently |: Cross-site scripting
Rental and Booking Manager for Bike, Car, Dress, Resort with WooCommerce Integration – WpRently | is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVDPending
Jun 23, 2023 CVE-2023-35048
Booking And Rental Manager For Woocommerce: Cross-site scripting
Booking And Rental Manager For Woocommerce is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.9
NVD4.8