CVE-2024-2441

The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.6.8 allows direct access to menus, allowing an authenticated user with subscriber privileges or above, to bypass authorization and access settings of the VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.6.8's they shouldn't be allowed to.
Configurations

No configuration.

History

14 Mar 2025, 01:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.1
CWE CWE-285

21 Nov 2024, 09:09

Type Values Removed Values Added
References () https://wpscan.com/vulnerability/9647e273-5724-4a02-868d-9b79f4bb2b79/ - () https://wpscan.com/vulnerability/9647e273-5724-4a02-868d-9b79f4bb2b79/ -
Summary
  • (es) El complemento VikBooking Hotel Booking Engine & PMS WordPress anterior a 1.6.8 permite el acceso directo a los menús, lo que permite a un usuario autenticado con privilegios de suscriptor o superiores omitir la autorización y acceder a la configuración del complemento VikBooking Hotel Booking Engine & PMS WordPress anterior a 1.6.8. no debería permitírselo.

14 May 2024, 15:19

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-14 15:19

Updated : 2025-03-14 01:15


NVD link : CVE-2024-2441

Mitre link : CVE-2024-2441

CVE.ORG link : CVE-2024-2441


JSON object : View

Products Affected

No product.

CWE
CWE-285

Improper Authorization