medium · CVSS v3 4.3 · EPSS 0.0018
CVE-2026-91025
The Booking Manager WordPress plugin before 2.1.21 does not verify that a request to modify a user's Booking Manager Wor…
Description
The Booking Manager WordPress plugin before 2.1.21 does not verify that a request to modify a user's Booking Manager WordPress plugin before 2.1.21-specific settings targets the requesting user's own account, allowing any authenticated user with subscriber-level access and above to create or overwrite the Booking Manager WordPress plugin before 2.1.21's per-user settings on arbitrary users, including administrators.
Scores
- Severity
- medium
- CVSS v2
- 4
- CVSS v3
- 4.3
- CVSS v4
- —
- EPSS
- 0.0018