WordPress security by component
Booking and Rental Manager
Plugin description
Booking and Rental Manager is a WordPress component with 15 published CVE records in this archive. The latest tracked vulnerability was published Jul 27, 2026; the highest CVE/CNA score is 8.8.
Plugin slug:
booking-and-rental-manager-for-woocommerceLatest vulnerability
CVE-2026-59532: Booking and Rental Manager permits unauthenticated price manipulation
Booking and Rental Manager through 2.7.2 accepts attacker-controlled pricing input through an unauthenticated booking or rental flow without enforcing the server-authorized amount. An attacker can manipulate a transaction price. The Patchstack CNA record does not disclose the route, action, price parameter, validation function, affected product types or whether payment completion is required.
| Safe version |
|
||
|---|---|---|---|
| Jul 27, 2026 |
CVE-2026-59532
Booking and Rental Manager permits unauthenticated price manipulation
Booking and Rental Manager through 2.7.2 accepts attacker-controlled pricing input through an unauthenticated booking or rental flow without enforcing the server-authorized amount. An attacker can manipulate a transaction price. The Patchstack CNA record does not disclose the route, action, price parameter, validation function, affected product types or whether payment completion is required.
|
2.7.3 |
CVE7.5
NVDPending
|
| Jul 13, 2026 |
CVE-2026-57404
Booking and Rental Manager: A security weakness
Booking and Rental Manager is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 2.6.9.
|
2.7.0 |
CVE6.5
NVDPending
|
| Jun 26, 2026 |
CVE-2026-57660
Booking and Rental Manager: A security weakness
Booking and Rental Manager is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 2.7.1.
|
2.7.2 |
CVE5.3
NVDPending
|
| Mar 25, 2026 |
CVE-2026-23972
Booking and Rental Manager: A security weakness
Booking and Rental Manager is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 2.6.0.
|
2.6.1 |
CVE6.5
NVDPending
|
| Feb 20, 2026 |
CVE-2025-69328
Booking and Rental Manager: Code execution
Booking and Rental Manager is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
|
See mitigation notes |
CVE8.8
NVDPending
|
| Dec 18, 2025 |
CVE-2025-64266
Booking and Rental Manager: Code execution
Booking and Rental Manager is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
|
See mitigation notes |
CVE8.8
NVDPending
|
| Nov 06, 2025 |
CVE-2025-49904
Booking and Rental Manager: Cross-site scripting
Booking and Rental Manager is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE7.1
NVDPending
|
| Jun 02, 2025 |
CVE-2025-47585
Booking and Rental Manager: A security weakness
Booking and Rental Manager is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Apr 24, 2025 |
CVE-2025-39390
Booking and Rental Manager: A security weakness
Booking and Rental Manager is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Apr 17, 2025 |
CVE-2025-39457
Booking and Rental Manager: A security weakness
Booking and Rental Manager is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Apr 15, 2025 |
CVE-2025-27011
Booking and Rental Manager: Filesystem traversal
Booking and Rental Manager is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
|
See mitigation notes |
CVE7.5
NVDPending
|
| Mar 15, 2025 |
CVE-2025-26921
Booking and Rental Manager: Code execution
Booking and Rental Manager is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
|
See mitigation notes |
CVE8.8
NVDPending
|
| Jan 31, 2025 |
CVE-2025-22720
Booking and Rental Manager: A security weakness
Booking and Rental Manager is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.8
NVDPending
|
| Jan 11, 2025 |
CVE-2024-12412
Rental and Booking Manager for Bike, Car, Dress, Resort with WooCommerce Integration – WpRently |: Cross-site scripting
Rental and Booking Manager for Bike, Car, Dress, Resort with WooCommerce Integration – WpRently | is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVDPending
|
| Jun 23, 2023 |
CVE-2023-35048
Booking And Rental Manager For Woocommerce: Cross-site scripting
Booking And Rental Manager For Woocommerce is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.9
NVD4.8
|