Impact
Subscriber accounts in the Booking Hub WordPress plugin up to version 1.3.0 can be exploited to gain higher privileges, allowing a normal user to perform actions reserved for administrators. This privilege escalation is due to improper privilege management and is identified as CWE-266. The vulnerability can compromise the integrity of the site by enabling unauthorized configuration changes, data access, or other privileged operations.
Affected Systems
LiquidThemes’ Booking Hub WordPress plugin, versions up to and including 1.3.0, is affected. Users deployed on WordPress sites that host this plugin must assess whether they are running a vulnerable version.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, and while the EPSS score is missing, the lack of a KEV listing suggests it may not be actively exploited yet. The likely attack vector is via the plugin's front‑end functionality accessible to any logged‑in subscriber. An attacker can trigger the escalation by interacting with a manipulated request that the plugin processes without proper privilege checks. The high CVSS score reflects the potential for full administrative access, so the vulnerability poses significant risk to confidentiality, integrity, and availability of the affected WordPress site.
OpenCVE Enrichment