The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.6.8 allows direct access to menus, allowing an authenticated user with subscriber privileges or above, to bypass authorization and access settings of the VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.6.8's they shouldn't be allowed to.
History

Mon, 05 May 2025 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Vikwp
Vikwp vikbooking Hotel Booking Engine \& Pms
CPEs cpe:2.3:a:vikwp:vikbooking_hotel_booking_engine_\&_pms:*:*:*:*:*:wordpress:*:*
Vendors & Products Vikwp
Vikwp vikbooking Hotel Booking Engine \& Pms

Fri, 14 Mar 2025 01:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2024-05-10T06:00:02.156Z

Updated: 2025-03-14T00:35:04.454Z

Reserved: 2024-03-13T21:15:48.984Z

Link: CVE-2024-2441

cve-icon Vulnrichment

Updated: 2024-08-01T19:11:53.563Z

cve-icon NVD

Status : Analyzed

Published: 2024-05-14T15:19:20.063

Modified: 2025-05-05T17:12:21.360

Link: CVE-2024-2441

cve-icon Redhat

No data.