Impact
The Booking Calendar plugin allows an authenticated user with Editor level permissions or higher to write arbitrary WordPress options through the wpbc_ajax_option_save AJAX action. The underlying save routine applies option safeguards only to names registered via register_option_policy(). For any unregistered option name, the policy checks are bypassed, enabling the attacker to pass an attacker‑controlled data_name parameter through sanitize_key() and write it directly to update_option(). By setting core options like default_role=administrator and users_can_register=1, an attacker can create a new Administrator account and fully control the site. This is a classic example of CWE‑269 Privilege Escalation.
Affected Systems
WordPress installations that include the Booking Calendar plugin version 11.8.2 or any earlier release. The plugin is distributed by wpdevelop and is active on sites where users have Editor or higher access rights. The vulnerability manifests on the server side when the wpbc_ajax_option_save handler processes POST requests to admin-ajax.php.
Risk and Exploitability
The CVSS score of 7.2 indicates moderate to high severity, while the EPSS score of less than 1% suggests a low but non‑zero probability of exploitation. The vulnerability is not currently listed in the CISA KEV catalog, implying no widespread exploitation yet. The likely attack vector is an authenticated editor who submits a crafted POST request to admin-ajax.php, obtains a valid nonce via rest‑nonce, and sets data_name to a core option such as default_role. The absence of meaningful nonce validation and the bypass of option policy checks make the exploitation relatively straightforward for a user with any non‑administrator role.
OpenCVE Enrichment