CVE-2024-2441

The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.6.8 allows direct access to menus, allowing an authenticated user with subscriber privileges or above, to bypass authorization and access settings of the VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.6.8's they shouldn't be allowed to.
Configurations

Configuration 1 (hide)

cpe:2.3:a:vikwp:vikbooking_hotel_booking_engine_\&_pms:*:*:*:*:*:wordpress:*:*

History

05 May 2025, 17:12

Type Values Removed Values Added
First Time Vikwp
Vikwp vikbooking Hotel Booking Engine \& Pms
CPE cpe:2.3:a:vikwp:vikbooking_hotel_booking_engine_\&_pms:*:*:*:*:*:wordpress:*:*
References () https://wpscan.com/vulnerability/9647e273-5724-4a02-868d-9b79f4bb2b79/ - () https://wpscan.com/vulnerability/9647e273-5724-4a02-868d-9b79f4bb2b79/ - Exploit, Third Party Advisory

14 Mar 2025, 01:15

Type Values Removed Values Added
CWE CWE-285
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.1

Information

Published : 2024-05-14 15:19

Updated : 2025-05-05 17:12


NVD link : CVE-2024-2441

Mitre link : CVE-2024-2441

CVE.ORG link : CVE-2024-2441


JSON object : View

Products Affected

vikwp

  • vikbooking_hotel_booking_engine_\&_pms
CWE
CWE-285

Improper Authorization