CVE-2025-39457

CVSS 3.1 Score 5.3 of 10 (medium)

Details

Published Apr 17, 2025
CWE ID 862

Summary

CVE-2025-39457 is a Missing Authorization vulnerability affecting the magepeopleteam Booking and Rental Manager from versions n/a through 2.2.8. An attacker can exploit this issue by taking advantage of incorrectly configured access control security levels, potentially gaining unauthorized access to sensitive information or functionality. This vulnerability could lead to significant security risks and potential data breaches. It is recommended that users of the Booking and Rental Manager upgrade to a patched version as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Booking And Rental Manager Plugin

Affected Vendors

  • WordPress