Executive brief
Booking Hub is a WordPress plugin for managing appointment and event bookings. A privilege escalation vulnerability allows low-privilege users (such as subscribers) to gain administrator access and take full control of affected websites. This could lead to data theft, malware installation, or complete compromise of customer booking information and website operations.
Technical details
This is a privilege escalation vulnerability in the Booking Hub WordPress plugin caused by incorrect privilege assignment. An attacker with low-privilege access (Subscriber role or equivalent) can escalate privileges to Administrator level without requiring additional authentication or user interaction. The vulnerability affects Booking Hub through version 1.3.1. No official patch has been released as of the advisory date. Attack impact includes full site compromise with ability to modify content, access sensitive data, and install malicious code.
Affected products
- LiquidThemes Booking Hub through 1.3.1
Timeline
- 2026-09-02: disclosed
- 2026-02-21: other: Vulnerability reported