CVE-2024-2441: VikBooking < 1.6.8 - Insecure Direct Object References

Description

The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.6.8 allows direct access to menus, allowing an authenticated user with subscriber privileges or above, to bypass authorization and access settings of the VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.6.8's they shouldn't be allowed to.

Classification

CVE ID: CVE-2024-2441

Problem Types

CWE-639 Authorization Bypass Through User-Controlled Key

Affected Products

Vendor: Unknown

Product: VikBooking Hotel Booking Engine & PMS

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.36% (probability of being exploited)

EPSS Percentile: 55.57% (scored less or equal to compared to others)

EPSS Date: 2025-04-11 (when was this score calculated)

Stakeholder-Specific Vulnerability Categorization (SSVC)

SSVC Exploitation: none

SSVC Technical Impact: partial

SSVC Automatable: false

References

https://nvd.nist.gov/vuln/detail/CVE-2024-2441
https://wpscan.com/vulnerability/9647e273-5724-4a02-868d-9b79f4bb2b79/

Timeline