Impact
Subscriber users of the Booking Hub plugin can exploit a flaw that allows them to elevate their privileges to higher roles within WordPress. The vulnerability is a form of privilege management error, identified as CWE-266, which permits an attacker to bypass normal access controls and gain administrative capabilities. If successful, the attacker could modify site settings, view or delete content, or manipulate booking data, compromising the integrity and confidentiality of the site and potentially leading to broader system compromise.
Affected Systems
WordPress sites that have the Booking Hub plugin by LiquidThemes installed at version 1.3.1 or earlier are affected. Any instance running any lower revision of those versions is susceptible. The vulnerability is tied specifically to the plugin; the core WordPress installation is not directly impacted.
Risk and Exploitability
The CVSS score of 8.8 indicates a high impact and high exploitability classification. Although the EPSS value is not available, the fact that the vulnerability is not listed in the CISA KEV catalog suggests it has not yet been widely observed in the wild. The attack vector is inferred to be local or through an authenticated subscriber account, as the flaw allows privilege escalation from a standard user role. If an attacker can gain or create a subscriber account, they are likely able to leverage the flaw without additional network access, making the risk relatively high for sites with unrestricted user registration.
OpenCVE Enrichment