CVE-2024-2441

The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.6.8 allows direct access to menus, allowing an authenticated user with subscriber privileges or above, to bypass authorization and access settings of the VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.6.8's they shouldn't be allowed to.
Configurations

No configuration.

History

14 Mar 2025, 01:15

Type Values Removed Values Added
CWE CWE-285
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.1

Information

Published : 2024-05-14 15:19

Updated : 2025-03-14 01:15


NVD link : CVE-2024-2441

Mitre link : CVE-2024-2441

CVE.ORG link : CVE-2024-2441


JSON object : View

Products Affected

No product.

CWE
CWE-285

Improper Authorization