CVE-2024-2441
HIGH 8.1EPSS 0.6%
The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.6.8 allows direct access to menus, allowing an authenticated user with subscriber privileges or above, to bypass authorization and access settings of the VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.6.8's they shouldn't be allowed to.
- CVSS v3.1
- 8.1 HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N - EPSS
- 0.61% chance of exploitation in the next 30 days, 47th percentile
- Published
- 2024-05-10
- Updated
- 2025-03-14