CVE-2026-59532

MagePeople · Booking and Rental Manager

A price manipulation vulnerability exists in the Booking and Rental Manager plugin for WordPress, allowing unauthenticated attackers to modify booking costs via improper input validation.

Executive summary

An unauthenticated price manipulation vulnerability in the Booking and Rental Manager plugin poses a high risk to business revenue and integrity.

Vulnerability

The vulnerability is categorized as CWE-1284, which involves improper validation of specified quantities in input. This allows unauthenticated attackers to manipulate price calculations during the booking process.

Business impact

Successful exploitation of this flaw allows unauthorized actors to alter transaction values, leading to direct financial loss and potential degradation of business operations. Given the CVSS score of 7.5, this represents a high-severity risk that could be exploited at scale due to the lack of required authentication.

Remediation

Immediate Action: Update the WordPress Booking and Rental Manager plugin to version 2.7.3 or later to resolve the input validation flaw.

Proactive Monitoring: Review WooCommerce order logs and transaction histories for anomalous price points or booking quantities that deviate from standard pricing structures.

Compensating Controls: Implement a Web Application Firewall (WAF) with rules configured to block suspicious requests targeting the plugin booking parameters until the patch is applied.

Exploitation status

Public Exploit Available: No

Analyst recommendation

The vulnerability presents a clear threat to the financial integrity of e-commerce platforms using this plugin. Administrators should prioritize updating to version 2.7.3 immediately to prevent potential revenue manipulation and ensure transaction accuracy.