CVE-2026-81769
Privilege Escalation via Incorrect Role Assignment in LiquidThemes Booking Hub
CVE-2026-81769 is an incorrect privilege assignment flaw (CWE-266) in the Booking Hub WordPress plugin by LiquidThemes that allows privilege escalation. Because the CVSS vector requires network access, low complexity, and an attacker already holding a low-privileged account (PR:L) with no user interaction, exploitation likely involves a crafted request sent from a basic authenticated session that the plugin mishandles, granting the attacker a higher-privileged role. A successful attacker gains full control over the affected WordPress site with high confidentiality, integrity, and availability impact, effectively enabling site takeover. Any WordPress site running Booking Hub version 1.3.1 or earlier is affected. There is no known exploitation in the wild, no public proof-of-concept, and the EPSS score of 0.3% (21st percentile) suggests current near-term exploitation risk is low.
What to do: Update Booking Hub to a fixed release (anything newer than 1.3.1 published by LiquidThemes) as soon as it is available, since the flaw is trivially exploitable by any low-privileged account. In the interim, audit WordPress user accounts for unexpected role assignments or unfamiliar administrator accounts, and restrict or disable open user registration on affected sites. Check the vendor changelog and the WordPress.org plugin page for the patched version number.
| LiquidThemes Booking Hub | all versions through 1.3.1 (n/a to 1.3.1) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect Privilege Assignment vulnerability in LiquidThemes Booking Hub allows Privilege Escalation. This issue affects Booking Hub: from n/a through 1.3.1.
- Ecosystems
- WordPress
- Weakness
- CWE-266
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.