Junglewise Threat Intelligence

CVE-2026-59541: Hakan Ozevin WP BASE Booking privilege escalation

CVE-2026-59541 · Severity: high · CVSS 8.8 · Published 2026-07-23

Technologies: Hakan Ozevin WP BASE Booking.

Executive brief

A security vulnerability in the WP BASE Booking plugin for WordPress allows users with low-level accounts, such as subscribers, to gain unauthorized administrative privileges. This plugin is used to manage appointments, services, and events on websites. If exploited, an attacker could take full control of the website, potentially leading to data theft, site defacement, or complete service disruption.

Technical details

The WP BASE Booking plugin for WordPress (versions <= 6.3.1) contains a privilege escalation vulnerability classified as Incorrect Privilege Assignment (CWE-266). The flaw allows an authenticated attacker with minimal 'Subscriber' permissions to bypass intended access controls and elevate their privileges to a higher level, such as Administrator. This is achieved via a network-based attack without requiring user interaction. The vulnerability was addressed in version 6.3.2.

Affected products

  • Hakan Ozevin WP BASE Booking <= 6.3.1

Timeline

  • 2026-07-03: other: Reported by researcher Afan
  • 2026-07-22: advisory: Patchstack advisory published
  • 2026-07-23: disclosed: NVD publication date
  • 2026-07-23: patched: Version 6.3.2 released to address the issue

References