CVE-2024-2441

The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.6.8 allows direct access to menus, allowing an authenticated user with subscriber privileges or above, to bypass authorization and access settings of the VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.6.8's they shouldn't be allowed to.
Configurations

Configuration 1 (hide)

cpe:2.3:a:vikwp:vikbooking_hotel_booking_engine_\&_pms:*:*:*:*:*:wordpress:*:*

History

05 May 2025, 17:12

Type Values Removed Values Added
First Time Vikwp
Vikwp vikbooking Hotel Booking Engine \& Pms
References () https://wpscan.com/vulnerability/9647e273-5724-4a02-868d-9b79f4bb2b79/ - () https://wpscan.com/vulnerability/9647e273-5724-4a02-868d-9b79f4bb2b79/ - Exploit, Third Party Advisory
CPE cpe:2.3:a:vikwp:vikbooking_hotel_booking_engine_\&_pms:*:*:*:*:*:wordpress:*:*

14 Mar 2025, 01:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.1
CWE CWE-285

21 Nov 2024, 09:09

Type Values Removed Values Added
References () https://wpscan.com/vulnerability/9647e273-5724-4a02-868d-9b79f4bb2b79/ - () https://wpscan.com/vulnerability/9647e273-5724-4a02-868d-9b79f4bb2b79/ -
Summary
  • (es) El complemento VikBooking Hotel Booking Engine & PMS WordPress anterior a 1.6.8 permite el acceso directo a los menús, lo que permite a un usuario autenticado con privilegios de suscriptor o superiores omitir la autorización y acceder a la configuración del complemento VikBooking Hotel Booking Engine & PMS WordPress anterior a 1.6.8. no debería permitírselo.

14 May 2024, 15:19

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-14 15:19

Updated : 2025-05-05 17:12


NVD link : CVE-2024-2441

Mitre link : CVE-2024-2441

CVE.ORG link : CVE-2024-2441


JSON object : View

Products Affected

vikwp

  • vikbooking_hotel_booking_engine_\&_pms
CWE
CWE-285

Improper Authorization