plugin

Booking And Rental Manager For Woocommerce Vulnerabilities

27 known security issues reported for the Booking And Rental Manager For Woocommerce WordPress plugin. Most recent disclosed Aug 24, 2026.

5 high 11 medium

Running Booking And Rental Manager For Woocommerce on your site? Check whether your installed version is affected.

Scan your site free

Booking and Rental Manager for Bike | Car | Resort | Appointment | Dress | Equipment <= 2.7.5 - Missing Authorization

medium

The Booking and Rental Manager for Bike | Car | Resort | Appointment | Dress | Equipment plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 2.7.5. This is due to a missing capability check on a function. This makes it possible for unauthenticated attackers to perform an unau...

CVSS:
5.3
Affected:
up to 2.7.5
Fixed in:
2.7.6
Disclosed:
Aug 24, 2026

CVE-2026-78258 on NVD →

Booking and Rental Manager for Bike | Car | Resort | Appointment | Dress | Equipment <= 2.7.2 - Unauthenticated Price Maniputlation

medium

The Booking and Rental Manager for Bike | Car | Resort | Appointment | Dress | Equipment plugin for WordPress is vulnerable to price manipulation in all versions up to, and including, 2.7.2. This makes it possible for unauthenticated attackers to alter the price of bookings.

CVSS:
5.3
Affected:
up to 2.7.2
Fixed in:
2.7.3
Disclosed:
Jul 23, 2026

CVE-2026-59532 on NVD →

Booking and Rental Manager <= 2.6.9 - Missing Authorization

medium

The Booking and Rental Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.6.9. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 2.6.9
Fixed in:
2.7.0
Disclosed:
Jul 8, 2026

CVE-2026-57404 on NVD →

Booking and Rental Manager for Bike | Car | Resort | Appointment | Dress | Equipment <= 2.7.1 - Missing Authorization

medium

The Booking and Rental Manager for Bike | Car | Resort | Appointment | Dress | Equipment plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.7.1. This makes it possible for unauthenticated attackers to perform an unauthorized acti...

CVSS:
5.3
Affected:
up to 2.7.1
Fixed in:
2.7.2
Disclosed:
Jun 26, 2026

CVE-2026-57660 on NVD →

Booking and Rental Manager for Bike | Car | Resort | Appointment | Dress | Equipment <= 2.6.0 - Missing Authorization

medium

The Booking and Rental Manager for Bike | Car | Resort | Appointment | Dress | Equipment plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.6.0. This makes it possible for authenticated attackers, with Subscriber-level access...

CVSS:
4.3
Affected:
up to 2.6.0
Fixed in:
2.6.1
Disclosed:
Mar 23, 2026

CVE-2026-23972 on NVD →

Booking and Rental Manager for Bike | Car | Resort | Appointment | Dress | Equipment [booking-and-rental-manager-for-woocommerce] <= 2.5.9 (unfixed)

unknown

[en] Deserialization of Untrusted Data vulnerability in magepeopleteam Booking and Rental Manager booking-and-rental-manager-for-woocommerce allows Object Injection.This issue affects Booking and Rental Manager: from n/a through <= 2.5.9.

Affected:
up to 2.5.9
Fix:
No patched version reported
Disclosed:
Feb 20, 2026

CVE-2025-69328 on NVD →

Booking and Rental Manager <= 2.5.9 - Authenticated (Contributor+) PHP Object Injection

high

The Booking and Rental Manager plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.5.9 via deserialization of untrusted input. This makes it possible for authenticated attackers, with contributor-level access and above, to inject a PHP Object. No known POP chain is present in...

CVSS:
7.5
Affected:
up to 2.5.9
Fixed in:
2.6.0
Disclosed:
Feb 9, 2026

CVE-2025-69328 on NVD →

Booking and Rental Manager for Bike | Car | Resort | Appointment | Dress | Equipment [booking-and-rental-manager-for-woocommerce] <= 2.5.4 (unfixed)

unknown

[en] Deserialization of Untrusted Data vulnerability in magepeopleteam Booking and Rental Manager booking-and-rental-manager-for-woocommerce allows Object Injection.This issue affects Booking and Rental Manager: from n/a through <= 2.5.4.

Affected:
up to 2.5.4
Fix:
No patched version reported
Disclosed:
Dec 18, 2025

CVE-2025-64266 on NVD →

Booking and Rental Manager for Bike | Car | Resort | Appointment | Dress | Equipment [booking-and-rental-manager-for-woocommerce] <= 2.5.3 (unfixed)

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in magepeopleteam Booking and Rental Manager booking-and-rental-manager-for-woocommerce allows Reflected XSS.This issue affects Booking and Rental Manager: from n/a through <= 2.5.3.

Affected:
up to 2.5.3
Fix:
No patched version reported
Disclosed:
Nov 6, 2025

CVE-2025-49904 on NVD →

Booking and Rental Manager <= 2.5.3 - Unauthenticated Stored Cross-Site Scripting

high

The Booking and Rental Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.5.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a...

CVSS:
7.2
Affected:
up to 2.5.3
Fixed in:
2.5.4
Disclosed:
Nov 1, 2025

CVE-2025-49904 on NVD →

Booking and Rental Manager <= 2.5.4 - Authenticated (Contributor+) PHP Object Injection

high

The Booking and Rental Manager plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.5.4 via deserialization of untrusted input. This makes it possible for authenticated attackers, with contributor-level access and above, to inject a PHP Object. No known POP chain is present in...

CVSS:
7.5
Affected:
up to 2.5.4
Fixed in:
2.5.5
Disclosed:
Sep 20, 2025

CVE-2025-64266 on NVD →

Booking and Rental Manager for Bike | Car | Resort | Appointment | Dress | Equipment [booking-and-rental-manager-for-woocommerce] < 2.3.9

unknown

[en] Missing Authorization vulnerability in Mage people team Booking and Rental Manager allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Booking and Rental Manager: from n/a through 2.3.8.

Affected:
up to 2.3.9
Fixed in:
2.3.9
Disclosed:
Jun 2, 2025

CVE-2025-47585 on NVD →

Booking and Rental Manager <= 2.3.8 - Missing Authorization

medium

The Booking and Rental Manager for Bike | Car | Resort | Appointment | Dress | Equipment plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.3.8. This makes it possible for unauthenticated attackers to perform an unauthorized...

CVSS:
5.3
Affected:
up to 2.3.8
Fixed in:
2.3.9
Disclosed:
May 22, 2025

CVE-2025-47585 on NVD →

Booking and Rental Manager for Bike | Car | Resort | Appointment | Dress | Equipment [booking-and-rental-manager-for-woocommerce] < 2.3.7

unknown

[en] Missing Authorization vulnerability in magepeopleteam Booking and Rental Manager allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Booking and Rental Manager: from n/a through 2.3.8.

Affected:
up to 2.3.7
Fixed in:
2.3.7
Disclosed:
Apr 24, 2025

CVE-2025-39390 on NVD →

Booking and Rental Manager <= 2.3.6 - Missing Authorization

medium

The Booking and Rental Manager for Bike | Car | Resort | Appointment | Dress | Equipment plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.3.6. This makes it possible for unauthenticated attackers to perform an unauthorized...

CVSS:
5.3
Affected:
up to 2.3.6
Fixed in:
2.3.7
Disclosed:
Apr 18, 2025

CVE-2025-39390 on NVD →

Booking and Rental Manager <= 2.2.8 - Missing Authorization

medium

The Booking and Rental Manager for Bike | Car | Resort | Appointment | Dress | Equipment plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.2.8. This makes it possible for unauthenticated attackers to perform an unauthorized...

CVSS:
5.3
Affected:
up to 2.2.8
Fixed in:
2.2.9
Disclosed:
Apr 17, 2025

CVE-2025-39457 on NVD →

Booking and Rental Manager for Bike | Car | Resort | Appointment | Dress | Equipment [booking-and-rental-manager-for-woocommerce] < 2.2.9

unknown

[en] Missing Authorization vulnerability in magepeopleteam Booking and Rental Manager allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Booking and Rental Manager: from n/a through 2.2.8.

Affected:
up to 2.2.9
Fixed in:
2.2.9
Disclosed:
Apr 17, 2025

CVE-2025-39457 on NVD →

Booking and Rental Manager for Bike | Car | Resort | Appointment | Dress | Equipment [booking-and-rental-manager-for-woocommerce] < 2.2.9

unknown

[en] Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in magepeopleteam Booking and Rental Manager allows PHP Local File Inclusion. This issue affects Booking and Rental Manager: from n/a through 2.2.8.

Affected:
up to 2.2.9
Fixed in:
2.2.9
Disclosed:
Apr 15, 2025

CVE-2025-27011 on NVD →

Booking and Rental Manager <= 2.2.8 - Authenticated (Contributor+) Local File Inclusion

high

The Booking and Rental Manager plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.2.8. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in...

CVSS:
8.8
Affected:
up to 2.2.8
Fixed in:
2.2.9
Disclosed:
Apr 11, 2025

CVE-2025-27011 on NVD →

Booking and Rental Manager for Bike | Car | Resort | Appointment | Dress | Equipment [booking-and-rental-manager-for-woocommerce] < 2.2.7

unknown

[en] Deserialization of Untrusted Data vulnerability in magepeopleteam Booking and Rental Manager allows Object Injection. This issue affects Booking and Rental Manager: from n/a through 2.2.6.

Affected:
up to 2.2.7
Fixed in:
2.2.7
Disclosed:
Mar 15, 2025

CVE-2025-26921 on NVD →

Booking and Rental Manager for Bike | Car | Resort | Appointment | Dress | Equipment <= 2.2.6 - Authenticated (Contributor+) PHP Object Injection

high

The Booking and Rental Manager for Bike | Car | Resort | Appointment | Dress | Equipment plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.2.6 via deserialization of untrusted input. This makes it possible for authenticated attackers, with Contributor-level access and ab...

CVSS:
8.8
Affected:
up to 2.2.6
Fixed in:
2.2.7
Disclosed:
Feb 23, 2025

CVE-2025-26921 on NVD →

Booking and Rental Manager for Bike | Car | Resort | Appointment | Dress | Equipment [booking-and-rental-manager-for-woocommerce] < 2.2.2

unknown

[en] Missing Authorization vulnerability in MagePeople Team Booking and Rental Manager allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Booking and Rental Manager: from n/a through 2.2.1.

Affected:
up to 2.2.2
Fixed in:
2.2.2
Disclosed:
Jan 31, 2025

CVE-2025-22720 on NVD →

Booking and Rental Manager for Bike | Car | Resort | Appointment | Dress | Equipment plugin for WordPress <= 2.2.1 - Missing Authorization

medium

The Booking and Rental Manager for Bike | Car | Resort | Appointment | Dress | Equipment plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.2.1. This makes it possible for unauthenticated attackers to perform an unauthorized...

CVSS:
5.3
Affected:
up to 2.2.1
Fixed in:
2.2.2
Disclosed:
Jan 15, 2025

CVE-2025-22720 on NVD →

Booking and Rental Manager for Bike | Car | Resort | Appointment | Dress | Equipment [booking-and-rental-manager-for-woocommerce] < 2.2.2

unknown

[en] The Rental and Booking Manager for Bike, Car, Dress, Resort with WooCommerce Integration – WpRently | WordPress plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘active_tab’ parameter in all versions up to, and including, 2.2.1 due to insufficient input sanitization and output escap...

Affected:
up to 2.2.2
Fixed in:
2.2.2
Disclosed:
Jan 11, 2025

CVE-2024-12412 on NVD →

Rental and Booking Manager for Bike, Car, Dress, Resort with WooCommerce Integration – WpRently | WordPress plugin <= 2.2.1 - Reflected Cross-Site Scripting

medium

The Rental and Booking Manager for Bike, Car, Dress, Resort with WooCommerce Integration – WpRently | WordPress plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘active_tab’ parameter in all versions up to, and including, 2.2.1 due to insufficient input sanitization and output escaping....

CVSS:
6.1
Affected:
up to 2.2.1
Fixed in:
2.2.2
Disclosed:
Jan 10, 2025

CVE-2024-12412 on NVD →

Booking and Rental Manager for Bike | Car | Resort | Appointment | Dress | Equipment [booking-and-rental-manager-for-woocommerce] < 1.2.2

unknown

[en] Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in MagePeople Team Booking and Rental Manager for Bike plugin <= 1.2.1 versions.

Affected:
up to 1.2.2
Fixed in:
1.2.2
Disclosed:
Jun 23, 2023

CVE-2023-35048 on NVD →

Booking and Rental Manager <= 1.2.1 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The Booking and Rental Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 1.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject...

CVSS:
4.4
Affected:
up to 1.2.1
Fixed in:
1.2.2
Disclosed:
Jun 13, 2023

CVE-2023-35048 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database