PT-2024-20389 · WordPress · Vikbooking Hotel Booking Engine & Pms
Cyc707
·
Published
2024-05-10
·
Updated
2024-05-14
·
CVE-2024-2441
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
VikBooking Hotel Booking Engine & PMS WordPress plugin versions prior to 1.6.8
Description
The issue allows an authenticated user with subscriber privileges or above to bypass authorization and access settings they shouldn't be allowed to. This is due to direct access to menus being permitted.
Recommendations
For versions prior to 1.6.8, update to version 1.6.8 or later to resolve the issue. As a temporary workaround, consider restricting access to the settings of the VikBooking Hotel Booking Engine & PMS WordPress plugin to minimize the risk of exploitation.
Exploit
Fix
Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vikbooking Hotel Booking Engine & Pms