CVE-2026-25414
8.8iqonicdesign · WPBookit Pro
A privilege escalation vulnerability in the iqonicdesign WPBookit Pro plugin allows authenticated users to manipulate access controls due to incorrect privilege assignment.
Executive summary
A critical privilege escalation flaw in the WPBookit Pro WordPress plugin allows authenticated attackers to potentially gain unauthorized administrative access.
Vulnerability
This vulnerability is caused by an incorrect privilege assignment within the plugin, which allows an authenticated user with low privileges to escalate their permissions. The flaw is reachable via network vectors without user interaction, as indicated by the CVSS vector.
Business impact
The ability for a low-privileged user to escalate to administrative status poses a severe risk to the integrity and confidentiality of the WordPress environment. An attacker could leverage this access to modify site content, install malicious plugins, or exfiltrate sensitive database information. With a CVSS score of 8.8, this vulnerability is classified as High and requires immediate attention to prevent full site compromise.
Remediation
Immediate Action: Since a specific patched version is not currently identified, users should immediately deactivate and remove the WPBookit Pro plugin until a security update is released by iqonicdesign.
Proactive Monitoring: Audit user account activity and privilege changes within the WordPress dashboard to identify any unauthorized escalations or suspicious administrative actions.
Compensating Controls: Implement a Web Application Firewall (WAF) to filter malicious requests targeting plugin-specific endpoints, though this should be considered a temporary measure until the plugin can be safely updated or removed.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Given the severity of this privilege escalation vulnerability, security teams must prioritize the immediate removal or deactivation of the affected WPBookit Pro plugin. Monitor the vendor advisory closely for the release of a secure version and perform a thorough security audit of all user accounts created or modified while the vulnerable plugin was active.
Sources
Originally found and disclosed by Phat RiO | Patchstack Bug Bounty Program, per the CVE Program record.