CVE-2026-59541

Hakan Ozevin · WP BASE Booking

The WP BASE Booking WordPress plugin contains a privilege escalation vulnerability that allows authenticated users with subscriber access to elevate their privileges.

Executive summary

A critical privilege escalation vulnerability in the WP BASE Booking WordPress plugin allows authenticated users to gain unauthorized administrative access to the platform.

Vulnerability

This vulnerability is an incorrect privilege assignment (CWE-266) within the plugin, allowing an attacker who is already authenticated as a low-privileged subscriber to perform unauthorized actions or escalate their account privileges.

Business impact

The ability for a low-privileged user to escalate to administrative status poses a severe risk to the integrity and confidentiality of the entire WordPress site. An attacker who gains administrative control could modify content, inject malicious code, or exfiltrate sensitive customer booking data, leading to significant reputational damage and potential regulatory non-compliance. The CVSS score of 8.8 reflects the high severity of this risk in an enterprise environment.

Remediation

Immediate Action: Update the WP BASE Booking plugin to version 6.3.2 or later immediately.

Proactive Monitoring: Review user account activity logs for anomalous creations of new administrative accounts or unexpected changes to existing user roles.

Compensating Controls: Implement a Web Application Firewall (WAF) to filter malicious requests targeting known plugin vulnerabilities if an immediate update is not feasible.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the high CVSS score and the nature of the vulnerability, organizations should prioritize patching this plugin immediately. Failure to update allows any registered subscriber to potentially compromise the entire site, making this a critical maintenance task for all administrators.