VikBooking Hotel Booking Engine & PMS <= 1.6.7 - Missing Authorization
2024-04-19 00:00
cyc707Strategic Overview
StatusPatched in 1.6.8
Affected PluginVikBooking Hotel Booking Engine & PMS
Affected Version
<= 1.6.7CVSS5.4Medium
CVE
CVE-2024-2749Vulnerability Overview
The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to unauthorized access due to insufficient capability checking in all versions up to, and including, 1.6.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to modify categories and perform several unauthorized actions.
Technical Analysis
REMEDIATION: Update to version 1.6.8, or a newer patched version --- IDENTIFIER: CWE-862 (Missing Authorization) The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C