Junglewise Threat Intelligence

CVE-2026-32561: Booking Hub privilege escalation in WordPress plugin

CVE-2026-32561 · Severity: high · CVSS 8.8 · Published 2026-08-24

Executive brief

Booking Hub is a WordPress plugin for managing booking functionality on websites. A privilege escalation vulnerability in versions up to 1.3.0 allows low-privilege subscriber accounts to gain full administrative access to the affected website, giving attackers complete control over site content, user data, and configuration.

Technical details

The vulnerability is a privilege escalation flaw (OWASP A7: Identification and Authentication Failures) in the Booking Hub WordPress plugin versions 1.3.0 and earlier. A subscriber-level user (the lowest privilege user role in WordPress) can exploit this vulnerability to escalate their privileges to full administrator. The attack requires existing user account access (subscriber role minimum) but no additional user interaction. An attacker with a compromised or created subscriber account can gain complete administrative control over the WordPress installation. As of publication, no official patch has been released, though Patchstack has issued mitigation rules.

Affected products

  • Booking Hub Booking Hub 1.3.0 and earlier

Timeline

  • 2026-08-24: disclosed
  • 2026-06-26: other: Reported to vendor

References