Description
Subscriber Privilege Escalation in WP BASE Booking <= 6.3.1 versions.
Published: 2026-07-23
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows a subscriber to gain elevated privileges within the WordPress site by exploiting a flaw in the WP BASE Booking plugin. No further details on the attacker’s scope are provided. The issue is classified as CWE‑266, indicating improper access control.

Affected Systems

The affected product is the WP BASE Booking plugin developed by Hakan Ozevin. Versions up to and including 6.3.1 are vulnerable; any installation of these or earlier revisions should be updated.

Risk and Exploitability

The CVSS score of 8.8 indicates high severity, while the EPSS score of <1% reflects a low likelihood of exploitation at the time of this assessment. The vulnerability is not listed in CISA’s KEV catalog, suggesting no currently known widespread exploitation. Attackers would need to log in as a subscriber to the WordPress site and use the plugin’s functionality, implying the attack vector is through legitimate user interactions with the plugin interface.

Generated by OpenCVE AI on August 3, 2026 at 22:19 UTC.

Remediation

Vendor Solution

Update the WordPress WP BASE Booking Plugin to the latest available version (at least 6.3.2).


OpenCVE Recommended Actions

  • Update the WP BASE Booking Plugin to version 6.3.2 or later.
  • Review and restrict user roles, ensuring subscribers do not have unnecessary capabilities; configure the plugin to enforce proper access control in line with CWE‑266.
  • As a temporary workaround, limit access to the plugin’s management pages to administrators only.

Generated by OpenCVE AI on August 3, 2026 at 22:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 13:15:00 +0000

Type Values Removed Values Added
First Time appeared Hakan Ozevin
Hakan Ozevin wp Base Booking
Wordpress
Wordpress wordpress
Vendors & Products Hakan Ozevin
Hakan Ozevin wp Base Booking
Wordpress
Wordpress wordpress

Thu, 23 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Description Subscriber Privilege Escalation in WP BASE Booking <= 6.3.1 versions.
Title WordPress WP BASE Booking plugin <= 6.3.1 - Privilege Escalation vulnerability
Weaknesses CWE-266
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Hakan Ozevin Wp Base Booking
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-23T14:25:27.109Z

Reserved: 2026-07-05T21:27:56.024Z

Link: CVE-2026-59541

cve-icon Vulnrichment

Updated: 2026-07-23T14:25:21.808Z

cve-icon NVD

Status : Deferred

Published: 2026-07-23T12:18:32.943

Modified: 2026-07-23T15:17:25.353

Link: CVE-2026-59541

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T22:30:03Z

Weaknesses
  • CWE-266

    Incorrect Privilege Assignment