The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.6.8 allows direct access to menus, allowing an authenticated user with subscriber privileges or above, to bypass authorization and access settings of the VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.6.8's they shouldn't be allowed to.
History

Fri, 14 Mar 2025 01:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2025-03-14T00:35:04.454Z

Reserved: 2024-03-13T21:15:48.984Z

Link: CVE-2024-2441

cve-icon Vulnrichment

Updated: 2024-08-01T19:11:53.563Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-05-14T15:19:20.063

Modified: 2025-03-14T01:15:39.150

Link: CVE-2024-2441

cve-icon Redhat

No data.