PatchSiren

magepeopleteam CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH magepeopleteam CVE published 2026-07-27

CVE-2026-59532

CVE-2026-59532 is a HIGH severity vulnerability with a 7.5 CVSS score, affecting Booking and Rental Manager versions up to 2.7.2. This unauthenticated vulnerability could potentially allow attackers to manipulate booking and rental data. Users of the Booking and Rental Manager plugin for WooCommerce should assess their current version and consider updating to a patched version to mitigate potential risks. [truncated]

MEDIUM magepeopleteam CVE published 2026-07-13

CVE-2026-61985

A Missing Authorization vulnerability was found in the Car Rental Manager plugin. This issue allows for Exploiting Incorrectly Configured Access Control Security Levels. The vulnerability affects Car Rental Manager from n/a through version 1.3.7. The Car Rental Manager plugin's Missing Authorization vulnerability stems from incorrectly configured access control security levels, potentially allowing unauth [truncated]

MEDIUM magepeopleteam CVE published 2026-07-13

CVE-2026-57404

A Missing Authorization vulnerability exists in the Booking and Rental Manager plugin for WooCommerce, affecting versions up to and including 2.6.9. This issue allows for Exploiting Incorrectly Configured Access Control Security Levels, potentially leading to unauthorized access or modifications. The vulnerability has a CVSS score of 6.5 and a severity rating of MEDIUM. Users of the plugin should be aware [truncated]

MEDIUM magepeopleteam CVE published 2026-06-26

CVE-2026-57660

CVE-2026-57660 is a medium-severity vulnerability in the Booking and Rental Manager plugin for WordPress, versions up to 2.7.1. The vulnerability allows unauthenticated broken access control, potentially enabling attackers to access sensitive information or perform unauthorized actions. The CVSS score for this vulnerability is 5.3, indicating a medium severity level. The vulnerability was published on Jun [truncated]

MEDIUM magepeopleteam CVE published 2026-04-08

CVE-2026-39572

The Bus Ticket Booking with Seat Reservation plugin for WordPress, versions from n/a through < 5.6.5, is vulnerable to Exposure of Sensitive System Information to an Unauthorized Control Sphere. This issue allows the retrieval of embedded sensitive data. The vulnerability has a CVSS score of 4.3 and a severity of MEDIUM. Users should update to version 5.6.5 or later to address this vulnerability. It is cr [truncated]

MEDIUM magepeopleteam CVE published 2026-04-08

CVE-2026-39565

A Missing Authorization vulnerability in WpTravelly tour-booking-manager allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WpTravelly: from n/a through <= 2.1.7. The vulnerability has a CVSS score of 4.3 and is classified as MEDIUM severity. It was published on 2026-04-08T09:16:27.790Z and last modified on 2026-07-20T20:10:00.110Z. The vulnerability is related to [truncated]