PoC Index

CVE-2024-2441

HIGH 8.1EPSS 0.6%

The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.6.8 allows direct access to menus, allowing an authenticated user with subscriber privileges or above, to bypass authorization and access settings of the VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.6.8's they shouldn't be allowed to.

CVSS v3.1
8.1 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
EPSS
0.61% chance of exploitation in the next 30 days, 47th percentile
Published
2024-05-10
Updated
2025-03-14

Proof-of-concept exploits (1)

References

Related