Booking and Rental Manager for Bike | Car | Resort | Appointment | Dress | Equipment <= 2.7.2 - Unauthenticated Price Maniputlation

2026-07-23 00:00
dodoh4t

Vulnerability Overview

The Booking and Rental Manager for Bike | Car | Resort | Appointment | Dress | Equipment plugin for WordPress is vulnerable to price manipulation in all versions up to, and including, 2.7.2. This makes it possible for unauthenticated attackers to alter the price of bookings.

Technical Analysis

REMEDIATION: Update to version 2.7.3, or a newer patched version --- IDENTIFIER: CWE-20 (Improper Input Validation) The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C