Description
Incorrect Privilege Assignment vulnerability in LiquidThemes Booking Hub allows Privilege Escalation.

This issue affects Booking Hub: from n/a through 1.3.1.
Published: 2026-09-02
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Subscriber users of the Booking Hub plugin can exploit a flaw that allows them to elevate their privileges to higher roles within WordPress. The vulnerability is a form of privilege management error, identified as CWE-266, which permits an attacker to bypass normal access controls and gain administrative capabilities. If successful, the attacker could modify site settings, view or delete content, or manipulate booking data, compromising the integrity and confidentiality of the site and potentially leading to broader system compromise.

Affected Systems

WordPress sites that have the Booking Hub plugin by LiquidThemes installed at version 1.3.1 or earlier are affected. Any instance running any lower revision of those versions is susceptible. The vulnerability is tied specifically to the plugin; the core WordPress installation is not directly impacted.

Risk and Exploitability

The CVSS score of 8.8 indicates a high impact and high exploitability classification. Although the EPSS value is not available, the fact that the vulnerability is not listed in the CISA KEV catalog suggests it has not yet been widely observed in the wild. The attack vector is inferred to be local or through an authenticated subscriber account, as the flaw allows privilege escalation from a standard user role. If an attacker can gain or create a subscriber account, they are likely able to leverage the flaw without additional network access, making the risk relatively high for sites with unrestricted user registration.

Generated by OpenCVE AI on September 2, 2026 at 13:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Booking Hub to a version newer than 1.3.1. This patch removes the privilege escalation flaw.
  • If an upgrade is not immediately possible, temporarily disable or remove the plugin until a fixed version is available, thereby keeping the vulnerable code from executing.
  • Restrict the capabilities of subscriber roles via a security plugin or user role editor, ensuring they lack the permissions that could be abused by the flaw.

Generated by OpenCVE AI on September 2, 2026 at 13:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 02 Sep 2026 12:00:00 +0000

Type Values Removed Values Added
Description Subscriber Privilege Escalation in Booking Hub <= 1.3.1 versions. Incorrect Privilege Assignment vulnerability in LiquidThemes Booking Hub allows Privilege Escalation. This issue affects Booking Hub: from n/a through 1.3.1.

Wed, 02 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
Description Subscriber Privilege Escalation in Booking Hub <= 1.3.1 versions.
Title WordPress Booking Hub plugin <= 1.3.1 - Privilege Escalation vulnerability
Weaknesses CWE-266
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-09-02T11:44:46.392Z

Reserved: 2026-08-27T12:24:18.942Z

Link: CVE-2026-81769

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-02T12:17:12.913

Modified: 2026-09-02T13:54:48.797

Link: CVE-2026-81769

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T13:45:17Z

Weaknesses
  • CWE-266

    Incorrect Privilege Assignment