Description
Subscriber Privilege Escalation in Booking Hub <= 1.3.0 versions.
Published: 2026-08-24
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Subscriber accounts in the Booking Hub WordPress plugin up to version 1.3.0 can be exploited to gain higher privileges, allowing a normal user to perform actions reserved for administrators. This privilege escalation is due to improper privilege management and is identified as CWE-266. The vulnerability can compromise the integrity of the site by enabling unauthorized configuration changes, data access, or other privileged operations.

Affected Systems

LiquidThemes’ Booking Hub WordPress plugin, versions up to and including 1.3.0, is affected. Users deployed on WordPress sites that host this plugin must assess whether they are running a vulnerable version.

Risk and Exploitability

The CVSS score of 8.8 indicates high severity, and while the EPSS score is missing, the lack of a KEV listing suggests it may not be actively exploited yet. The likely attack vector is via the plugin's front‑end functionality accessible to any logged‑in subscriber. An attacker can trigger the escalation by interacting with a manipulated request that the plugin processes without proper privilege checks. The high CVSS score reflects the potential for full administrative access, so the vulnerability poses significant risk to confidentiality, integrity, and availability of the affected WordPress site.

Generated by OpenCVE AI on August 24, 2026 at 22:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Booking Hub plugin to the latest available version (≥ 1.3.1) to remove the privilege escalation flaw.
  • If an upgrade is not immediately possible, disable or delete the Booking Hub plugin to prevent the vulnerability from being exploitable.
  • Enforce strict role permissions for WordPress subscribers, ensuring they cannot perform administrative actions, and periodically review user capabilities for the plugin.

Generated by OpenCVE AI on August 24, 2026 at 22:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description Subscriber Privilege Escalation in Booking Hub <= 1.3.0 versions.
Title WordPress Booking Hub plugin <= 1.3.0 - Privilege Escalation vulnerability
Weaknesses CWE-266
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-24T21:31:28.568Z

Reserved: 2026-03-12T11:12:48.311Z

Link: CVE-2026-32561

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-24T22:16:52.157

Modified: 2026-08-24T22:16:52.157

Link: CVE-2026-32561

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T22:30:04Z

Weaknesses
  • CWE-266

    Incorrect Privilege Assignment