Magepeople Team · Booking/Rental Manager · CVE-2026-57660
**Name of the Vulnerable Software and Affected Versions**
Booking and Rental Manager versions prior to 2.7.2
**Description**
The Booking and Rental Manager plugin for WordPress contains a broken access control issue. This is caused by a missing capability check within a function, allowing unauthenticated attackers to perform unauthorized actions.
**Recommendations**
Update to a version newer than 2.7.1.