CVE-2026-32561
8.8LiquidThemes · Booking Hub
The Booking Hub WordPress plugin contains a privilege escalation vulnerability allowing authenticated subscribers to gain unauthorized elevated permissions.
Executive summary
A privilege escalation vulnerability in the LiquidThemes Booking Hub WordPress plugin allows low-privileged subscribers to perform unauthorized actions, posing a critical risk to site administration.
Vulnerability
This is a privilege escalation vulnerability (CWE-266) within the Booking Hub plugin. An authenticated user with subscriber-level access can manipulate plugin functions to gain higher privileges, effectively bypassing standard WordPress role-based access controls.
Business impact
Successful exploitation allows an attacker to gain administrative or elevated control over the WordPress site. This can result in complete site takeover, unauthorized data modification, malware injection, or the compromise of user databases, justifying the high CVSS score of 8.8.
Remediation
Immediate Action: Update the Booking Hub plugin to the latest patched version available from the vendor.
Proactive Monitoring: Review WordPress user activity logs for suspicious privilege changes or actions performed by accounts that should only have subscriber-level access.
Compensating Controls: Disable the Booking Hub plugin temporarily if an update is not immediately feasible, and implement a Web Application Firewall (WAF) to detect and block common privilege escalation attempts.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Site administrators using the Booking Hub plugin must update to the latest version immediately to prevent potential site-wide compromise. Regularly auditing user roles and permissions is recommended to minimize the impact of any similar future vulnerabilities.