CVE-2025-27011
CVSS 3.1 Score 7.5 of 10 (high)
Details
Summary
CVE-2025-27011 is a Filename Validation Error in the magepeopleteam Booking and Rental Manager PHP application. This vulnerability, classified as a PHP Remote File Inclusion (RFI), permits an attacker to include local files by manipulating the filename for an include or require statement. This issue poses a security risk, as an attacker could potentially access sensitive information or execute malicious code. The vulnerability affects versions of the Booking and Rental Manager software from n/a through 2.2.8. It is recommended that affected users upgrade to a patched version as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Booking And Rental Manager Plugin
Affected Vendors
- WordPress