The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.6.8's access control mechanism fails to properly restrict access to its settings, permitting any users that can access a menu to manipulate requests and perform unauthorized actions such as editing, renaming or deleting (categories for example) despite initial settings prohibiting such access. This vulnerability resembles broken access control, enabling unauthorized users to modify critical VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.6.8 configurations.
Metrics
Affected Vendors & Products
References
History
Mon, 05 May 2025 17:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Vikwp
Vikwp vikbooking Hotel Booking Engine \& Pms |
|
CPEs | cpe:2.3:a:vikwp:vikbooking_hotel_booking_engine_\&_pms:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Vikwp
Vikwp vikbooking Hotel Booking Engine \& Pms |

Status: PUBLISHED
Assigner: WPScan
Published: 2024-05-10T06:00:02.386Z
Updated: 2024-08-01T19:25:41.264Z
Reserved: 2024-03-20T19:43:06.323Z
Link: CVE-2024-2749

Updated: 2024-08-01T19:25:41.264Z

Status : Analyzed
Published: 2024-05-14T15:20:41.787
Modified: 2025-05-05T17:10:37.557
Link: CVE-2024-2749

No data.