ZeroHour

CVE-2026-81769

Privilege Escalation via Incorrect Role Assignment in LiquidThemes Booking Hub

CVSS 3.1
8.8 high
EPSS
<1%p21
Published
()
Modified
AI analysis

CVE-2026-81769 is an incorrect privilege assignment flaw (CWE-266) in the Booking Hub WordPress plugin by LiquidThemes that allows privilege escalation. Because the CVSS vector requires network access, low complexity, and an attacker already holding a low-privileged account (PR:L) with no user interaction, exploitation likely involves a crafted request sent from a basic authenticated session that the plugin mishandles, granting the attacker a higher-privileged role. A successful attacker gains full control over the affected WordPress site with high confidentiality, integrity, and availability impact, effectively enabling site takeover. Any WordPress site running Booking Hub version 1.3.1 or earlier is affected. There is no known exploitation in the wild, no public proof-of-concept, and the EPSS score of 0.3% (21st percentile) suggests current near-term exploitation risk is low.

What to do: Update Booking Hub to a fixed release (anything newer than 1.3.1 published by LiquidThemes) as soon as it is available, since the flaw is trivially exploitable by any low-privileged account. In the interim, audit WordPress user accounts for unexpected role assignments or unfamiliar administrator accounts, and restrict or disable open user registration on affected sites. Check the vendor changelog and the WordPress.org plugin page for the patched version number.

Affected
LiquidThemes Booking Huball versions through 1.3.1 (n/a to 1.3.1)
Estimated exposure
unknown — likely limited to the (presumably modest) installed base of this niche booking plugin — No active-install count or scan data was provided for the Booking Hub plugin, so only an order-of-magnitude guess is possible: as a specialized booking plugin from a single theme vendor rather than a mass-market utility, its installed base…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect Privilege Assignment vulnerability in LiquidThemes Booking Hub allows Privilege Escalation. This issue affects Booking Hub: from n/a through 1.3.1.

Ecosystems
WordPress
Weakness
CWE-266
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.