PT-2026-27844 · Magepeople Team · Booking/Rental Manager+1

Published

2026-03-25

·

Updated

2026-03-30

·

CVE-2026-23972

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Booking and Rental Manager versions n/a through 2.6.0
Description An authorization issue exists in magepeopleteam Booking and Rental Manager booking-and-rental-manager-for-woocommerce. This is due to incorrectly configured access control security levels, potentially allowing unauthorized access.
Recommendations Update Booking and Rental Manager to a version newer than 2.6.0.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-23972

Affected Products

Booking/Rental Manager
Taxi Booking Manager For Woocommerce