Sceawere

Vulnerability Detail

CVE-2026-27432UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

WP Rentals Authorization Bypass Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.4
Creation Date
4h ago
Vendor
sc Internet Vivoo
Product
WP Rentals
Attack Type
CWE-639 Authorization Bypass Through User-Controlled Key
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

Authorization Bypass Through User-Controlled Key vulnerability in sc Internet Vivoo WP Rentals allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP Rentals: from n/a before 3.16.0.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.4",
  "pubDate": "2026-09-04T09:17:10.543Z",
  "pubdate": "2026-09-04T09:17:10.543Z",
  "executiveSummary": "This vulnerability, classified as an Authorization Bypass Through User-Controlled Key, affects the WP Rentals plugin for WordPress. It stems from improperly configured access control security levels, allowing unauthorized users to gain elevated privileges or access restricted data.\nThe flaw exists within WP Rentals versions prior to 3.16.0. An unauthenticated or low-privileged attacker can exploit this misconfiguration to circumvent authorization checks intended to restrict access to sensitive functionalities.\nThe risk implication is significant as it potentially allows for unauthorized administrative actions or data exposure depending on the specific endpoint being targeted. Exploitation requires no complex preconditions beyond the existence of the misconfigured security check.\nBy manipulating user-controlled keys, an attacker can effectively bypass the intended application logic, leading to a complete breakdown of access control mechanisms within the affected WP Rentals component.",
  "technicalDetails": "The vulnerability resides in the access control logic of the WP Rentals plugin, specifically concerning the handling of user-controlled keys. The application fails to strictly validate the authorization context when processing requests that utilize these keys to determine the user's security level.\nThe root cause is a failure in the application's authorization framework to sanitize or verify the authenticity and scope of user-provided keys against the actual session identity. Instead of relying on server-side session validation, the plugin permits the manipulation of parameters to influence internal access control decisions.\nIn a typical attack flow, an attacker identifies an endpoint or function within the WP Rentals ecosystem that relies on a user-controlled key for permission assessment. By intercepting a request, the attacker modifies the key—often through parameter tampering—to represent a higher privilege level or a different user context.\nUpon receiving the malicious request, the server-side logic fails to cross-reference the provided key with the requester's legitimate session credentials. Consequently, the application processes the request as if it originated from an authorized or elevated user, bypassing the intended security guardrails.\nThe scope of exploitation extends to any functionality protected by these incorrectly configured access control checks. This can include, but is not limited to, unauthorized access to user management dashboards, modification of rental property settings, or retrieval of sensitive transaction information.\nBecause the vulnerability exists in the core authorization logic rather than a specific input field, it is highly impactful across the affected product versions. The lack of robust secondary verification ensures that once the primary check is bypassed, the attacker achieves the desired level of unauthorized access without requiring prior elevated credentials.\nThis vulnerability underscores a failure in the implementation of the Principle of Least Privilege, as the application implicitly trusts user-supplied input to enforce its internal security boundaries."
}
CVE-2026-27432: WP Rentals Authorization Bypass Vulnerability (MEDIUM Severity, CVSS: 5.4) - Sceawere