Junglewise Threat Intelligence

CVE-2026-39587: WP BASE Booking privilege escalation in WordPress plugin

CVE-2026-39587 · Severity: high · CVSS 8.1 · Published 2026-06-15

Technologies: WP BASE Booking. Vendors: WP BASE Booking.

Executive brief

A security vulnerability in the WP BASE Booking plugin for WordPress allows unauthorized individuals to gain administrative control over a website. This plugin is used to manage appointments, services, and events; an exploit could lead to a complete site takeover, data theft, or service disruption. Website owners should update to version 6.0.0 immediately to protect their operations and customer data.

Technical details

The WP BASE Booking plugin for WordPress (versions <= 5.9.0) contains a privilege escalation vulnerability classified under CWE-266 (Incorrect Privilege Assignment). The flaw allows an unauthenticated remote attacker to escalate their privileges, potentially gaining administrator-level access to the WordPress environment. While the attack complexity is rated as high, the impact is critical as it bypasses authentication requirements to compromise the integrity and confidentiality of the site. The issue is resolved in version 6.0.0.

Affected products

  • WP BASE Booking WP BASE Booking <= 5.9.0

Timeline

  • 2026-02-11: other: Reported by Jarno Vos
  • 2026-04-08: advisory: Patchstack advisory published
  • 2026-06-15: disclosed: NVD publication date

References

Related threats