CVE-2024-2441

The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.6.8 allows direct access to menus, allowing an authenticated user with subscriber privileges or above, to bypass authorization and access settings of the VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.6.8's they shouldn't be allowed to.
Configurations

Configuration 1 (hide)

cpe:2.3:a:vikwp:vikbooking_hotel_booking_engine_\&_pms:*:*:*:*:*:wordpress:*:*

History

No history.

Information

Published : 2024-05-14 15:19

Updated : 2025-05-05 17:12


NVD link : CVE-2024-2441

Mitre link : CVE-2024-2441

CVE.ORG link : CVE-2024-2441


JSON object : View

Products Affected

vikwp

  • vikbooking_hotel_booking_engine_\&_pms
CWE
CWE-285

Improper Authorization