WordPress DesignThemes Reservation Plugin Missing Authorization Vulnerability Allowing Access Control Bypass

Vulnerability

A missing authorization vulnerability has been identified in the WordPress DesignThemes Reservation Plugin, specifically in versions through 1.7. This vulnerability allows for the exploitation of improperly configured access control, enabling unauthorized users to change settings or access restricted features.

Impact

Exploitation of this vulnerability could lead to unauthorized changes in plugin settings, potentially allowing attackers to manipulate reservation data or other related functionalities.

Remediation

Users are advised to update to a version of the WordPress DesignThemes Reservation Plugin later than 1.7. For those unable to update, Patchstack offers a mitigation rule to block attacks until an official fix can be applied.

Added: Jan 22, 2026, 8:20 PM
Updated: Jan 22, 2026, 8:20 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
7.4
remediation
0.0
relevance
2.3
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.