← WordPress Vulnerabilities
WordPress security by component

Booking and Rental Manager

Booking and Rental Manager adds booking and rental management features for WooCommerce products, including availability, reservations, and rental schedules.

Booking and Rental Manager (booking-and-rental-manager-for-woocommerce) is a WordPress plugin with 19 published CVE records in this archive. The latest tracked vulnerability was published Sep 03, 2026; the highest published CVSS base score is 8.8.

Plugin slug: booking-and-rental-manager-for-woocommerce

CVE-2026-85303: Booking and Rental Manager permits stored cross-site scripting

Booking and Rental Manager through 2.7.7 allows a low-privilege authenticated user to store script-capable content. The payload can execute in the site's origin when another user views the affected booking or rental output.

PublishedSep 03, 2026
Known safe version2.7.8
Published vulnerabilities for booking-and-rental-manager-for-woocommerce
Safe version
Sep 03, 2026 CVE-2026-85303
Booking and Rental Manager permits stored cross-site scripting
Booking and Rental Manager through 2.7.7 allows a low-privilege authenticated user to store script-capable content. The payload can execute in the site's origin when another user views the affected booking or rental output.
2.7.8
CVE6.5
NVDPending
Aug 31, 2026 CVE-2026-81762
Booking and Rental Manager permits Subscriber-level unauthorized changes
Booking and Rental Manager through 2.7.6 allows a Subscriber to invoke an integrity-changing operation without the required authorization. The account can alter protected booking or plugin state outside its intended access.
2.7.7
CVE6.5
NVDPending
Aug 27, 2026 CVE-2026-78257
Booking and Rental Manager: Code execution
Booking and Rental Manager is affected by code execution. Exploitation requires an authenticated contributor account. Successful exploitation can run attacker-controlled code in the WordPress hosting account. The published affected range is n/a through 2.7.5.
2.7.6
CVE8.8
NVDPending
Aug 24, 2026 CVE-2026-78258
Booking and Rental Manager exposes protected data without authentication
Booking and Rental Manager through 2.7.5 exposes an operation without the authorization it requires. An unauthenticated requester can obtain protected data, and the CNA rates confidentiality impact as low.
2.7.6
CVE5.3
NVDPending
Jul 27, 2026 CVE-2026-59532
Booking and Rental Manager permits unauthenticated price manipulation
Booking and Rental Manager through 2.7.2 accepts attacker-controlled pricing input through an unauthenticated booking or rental flow without enforcing the server-authorized amount. An attacker can manipulate a transaction price.
2.7.3
CVE7.5
NVDPending
Jul 13, 2026 CVE-2026-57404
Booking and Rental Manager: A security weakness
Booking and Rental Manager is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 2.6.9.
2.7.0
CVE6.5
NVDPending
Jun 26, 2026 CVE-2026-57660
Booking and Rental Manager: Broken access control
Booking and Rental Manager is affected by broken access control. The vulnerable path is reachable without authentication. A successful request can reach data or an operation that should be restricted to another user or a more privileged role. The published affected range is n/a through 2.7.1.
2.7.2
CVE5.3
NVDPending
Mar 25, 2026 CVE-2026-23972
Booking and Rental Manager: A security weakness
Booking and Rental Manager is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 2.6.0.
2.6.1
CVE6.5
NVDPending
Feb 20, 2026 CVE-2025-69328
Booking and Rental Manager: Code execution
Booking and Rental Manager is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE8.8
NVDPending
Dec 18, 2025 CVE-2025-64266
Booking and Rental Manager: Code execution
Booking and Rental Manager is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE8.8
NVDPending
Nov 06, 2025 CVE-2025-49904
Booking and Rental Manager: Cross-site scripting
Booking and Rental Manager is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.1
NVDPending
Jun 02, 2025 CVE-2025-47585
Booking and Rental Manager: A security weakness
Booking and Rental Manager is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.5
NVDPending
Apr 24, 2025 CVE-2025-39390
Booking and Rental Manager: A security weakness
Booking and Rental Manager is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Apr 17, 2025 CVE-2025-39457
Booking and Rental Manager: A security weakness
Booking and Rental Manager is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Apr 15, 2025 CVE-2025-27011
Booking and Rental Manager: Filesystem traversal
Booking and Rental Manager is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE7.5
NVDPending
Mar 15, 2025 CVE-2025-26921
Booking and Rental Manager: Code execution
Booking and Rental Manager is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE8.8
NVDPending
Jan 31, 2025 CVE-2025-22720
Booking and Rental Manager: A security weakness
Booking and Rental Manager is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.8
NVDPending
Jan 11, 2025 CVE-2024-12412
Rental and Booking Manager for Bike, Car, Dress, Resort with WooCommerce Integration – WpRently |: Cross-site scripting
Rental and Booking Manager for Bike, Car, Dress, Resort with WooCommerce Integration – WpRently | is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVDPending
Jun 23, 2023 CVE-2023-35048
Booking And Rental Manager For Woocommerce: Cross-site scripting
Booking And Rental Manager For Woocommerce is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.9
NVD4.8