A vulnerability was found in Booking Activities Plugin up to 1.16.48.1 on WordPress. It has been declared as critical. This issue affects some unknown processing. The manipulation results in missing authorization.

This vulnerability is cataloged as CVE-2026-39525. The attack may be launched remotely. There is no exploit available.