The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.6.8 allows direct access to menus, allowing an authenticated user with subscriber privileges or above, to bypass authorization and access settings of the VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.6.8's they shouldn't be allowed to.
Metrics
Affected Vendors & Products
References
History
Fri, 14 Mar 2025 01:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-285 | |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-03-14T00:35:04.454Z
Reserved: 2024-03-13T21:15:48.984Z
Link: CVE-2024-2441

Updated: 2024-08-01T19:11:53.563Z

Status : Awaiting Analysis
Published: 2024-05-14T15:19:20.063
Modified: 2025-03-14T01:15:39.150
Link: CVE-2024-2441

No data.