CVE-2026-91025 PUBLISHED

Booking Manager < 2.1.21 - Subscriber+ Arbitrary User Plugin Meta Modification via IDOR

Assigner: WPScan
Reserved: 14.09.2026 Published: 23.09.2026 Updated: 23.09.2026

The Booking Manager WordPress plugin before 2.1.21 does not verify that a request to modify a user's Booking Manager WordPress plugin before 2.1.21-specific settings targets the requesting user's own account, allowing any authenticated user with subscriber-level access and above to create or overwrite the Booking Manager WordPress plugin before 2.1.21's per-user settings on arbitrary users, including administrators.

Product Status

Vendor Unknown
Product Booking Manager
Versions Default: unaffected
  • affected from 0 to 2.1.21 (excl.)

Credits

  • Choriyev Qahramon (ciprobe) finder
  • WPScan coordinator

References

Problem Types

  • CWE-639 Authorization Bypass Through User-Controlled Key CWE