Description
The Booking Calendar plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 11.8.2 via the `wpbc_ajax_option_save` AJAX action. The vulnerability exists because the `handle_ajax_save()` function applies per-option safeguards only to names explicitly registered via `register_option_policy()`, causing `get_option_policy()` to return an empty policy — bypassing all can_save, force_mode, and allowed_keys checks — for any unregistered option name, including core WordPress options, while an attacker-controlled `data_name` parameter passes through `sanitize_key()` and is written directly to `update_option()` without restriction. This makes it possible for authenticated attackers with Editor-level access and above to escalate their privileges to Administrator by writing core WordPress options such as `default_role=administrator` and `users_can_register=1`, then self-registering a new Administrator account. The nonce check does not meaningfully restrict this attack, as both the nonce value and nonce action are attacker-supplied POST parameters, and a valid nonce is trivially obtainable via `admin-ajax.php?action=rest-nonce`.
Published: 2026-09-18
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Patch Immediately
AI Analysis

Impact

The Booking Calendar plugin allows an authenticated user with Editor level permissions or higher to write arbitrary WordPress options through the wpbc_ajax_option_save AJAX action. The underlying save routine applies option safeguards only to names registered via register_option_policy(). For any unregistered option name, the policy checks are bypassed, enabling the attacker to pass an attacker‑controlled data_name parameter through sanitize_key() and write it directly to update_option(). By setting core options like default_role=administrator and users_can_register=1, an attacker can create a new Administrator account and fully control the site. This is a classic example of CWE‑269 Privilege Escalation.

Affected Systems

WordPress installations that include the Booking Calendar plugin version 11.8.2 or any earlier release. The plugin is distributed by wpdevelop and is active on sites where users have Editor or higher access rights. The vulnerability manifests on the server side when the wpbc_ajax_option_save handler processes POST requests to admin-ajax.php.

Risk and Exploitability

The CVSS score of 7.2 indicates moderate to high severity, while the EPSS score of less than 1% suggests a low but non‑zero probability of exploitation. The vulnerability is not currently listed in the CISA KEV catalog, implying no widespread exploitation yet. The likely attack vector is an authenticated editor who submits a crafted POST request to admin-ajax.php, obtains a valid nonce via rest‑nonce, and sets data_name to a core option such as default_role. The absence of meaningful nonce validation and the bypass of option policy checks make the exploitation relatively straightforward for a user with any non‑administrator role.

Generated by OpenCVE AI on September 19, 2026 at 20:34 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Booking Calendar to version 11.8.3 or later to ensure that handle_ajax_save() enforces per‑option policies for all option names.
  • If an upgrade is not immediately possible, remove Editor and any higher roles from the site or downgrade their capabilities so they can no longer edit core options (e.g., revoke the edit_users capability).
  • Audit WordPress options after the vulnerability ad‑hoc was discovered, reset any core options that were incorrectly configured, and verify that default_role remains the intended default.

Generated by OpenCVE AI on September 19, 2026 at 20:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Wpdevelop
Wpdevelop booking Calendar
Vendors & Products Wordpress
Wordpress wordpress
Wpdevelop
Wpdevelop booking Calendar

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 07:00:00 +0000

Type Values Removed Values Added
Description The Booking Calendar plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 11.8.2 via the `wpbc_ajax_option_save` AJAX action. The vulnerability exists because the `handle_ajax_save()` function applies per-option safeguards only to names explicitly registered via `register_option_policy()`, causing `get_option_policy()` to return an empty policy — bypassing all can_save, force_mode, and allowed_keys checks — for any unregistered option name, including core WordPress options, while an attacker-controlled `data_name` parameter passes through `sanitize_key()` and is written directly to `update_option()` without restriction. This makes it possible for authenticated attackers with Editor-level access and above to escalate their privileges to Administrator by writing core WordPress options such as `default_role=administrator` and `users_can_register=1`, then self-registering a new Administrator account. The nonce check does not meaningfully restrict this attack, as both the nonce value and nonce action are attacker-supplied POST parameters, and a valid nonce is trivially obtainable via `admin-ajax.php?action=rest-nonce`.
Title Booking Calendar <= 11.8.2 - Authenticated (Editor+) Privilege Escalation to 'data_name' Parameter
Weaknesses CWE-269
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Wordpress Wordpress
Wpdevelop Booking Calendar
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-09-18T18:32:21.018Z

Reserved: 2026-09-16T14:45:02.914Z

Link: CVE-2026-92619

cve-icon Vulnrichment

Updated: 2026-09-18T17:24:21.458Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T07:16:51.997

Modified: 2026-09-18T19:17:17.980

Link: CVE-2026-92619

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T20:45:17Z

Weaknesses
  • CWE-269

    Improper Privilege Management