{"id":"CVE-2026-91025","published":"2026-09-23T06:17:05.523","lastModified":"2026-09-23T18:12:32.050","description":"The Booking Manager  WordPress plugin before 2.1.21 does not verify that a request to modify a user's Booking Manager  WordPress plugin before 2.1.21-specific settings targets the requesting user's own account, allowing any authenticated user with subscriber-level access and above to create or overwrite the Booking Manager  WordPress plugin before 2.1.21's per-user settings on arbitrary users, including administrators.","cvssScore":4.3,"cvssSeverity":"MEDIUM","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","cwes":["CWE-639"],"vendors":[],"products":[],"references":[{"url":"https://wpscan.com/vulnerability/6e010e3e-78e8-4bfc-b880-d9a85cff2c2a/","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}