What is CVE-2026-57367?
This vulnerability in WP Booking System versions below 5.12.8.1 allows users with "Subscriber" role to access other users' booking data via broken access control. Updating to the latest version is recommended.
Azərbaycanca: Bu zəiflik WP Booking System plagininin 5.12.8.1-dən əvvəlki versiyalarında "Subscriber" roluna malik istifadəçilərə digər istifadəçilərin bron məlumatlarına icazəsiz giriş imkanı verir. Plaginin ən son versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-284
FAQ2
Which versions of the WP Booking System plugin are affected by CVE-2026-57367?
This vulnerability affects WP Booking System versions below 5.12.8.1.
What user role can exploit CVE-2026-57367 to access other users' booking data?
Users with the "Subscriber" role can exploit this vulnerability to gain unauthorized access to other users' booking data.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.