Sceawere

Vulnerability Detail

CVE-2026-81769UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Booking Hub Privilege Escalation Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
8.8
Creation Date
18h ago
Vendor
LiquidThemes
Product
Booking Hub
Attack Type
CWE-266 Incorrect Privilege Assignment
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Incorrect Privilege Assignment vulnerability in LiquidThemes Booking Hub allows Privilege Escalation. This issue affects Booking Hub: from n/a through 1.3.1.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.8",
  "pubDate": "2026-09-02T12:17:12.913Z",
  "pubdate": "2026-09-02T12:17:12.913Z",
  "executiveSummary": "The LiquidThemes Booking Hub plugin for WordPress is susceptible to an Incorrect Privilege Assignment vulnerability, which facilitates unauthorized privilege escalation.\nThis security flaw, affecting versions from n/a through 1.3.1, allows authenticated attackers with lower-level access to manipulate user role assignments.\nBy successfully exploiting this vulnerability, an attacker can elevate their own privileges to higher, more restricted roles, such as Administrator, granting them full control over the affected WordPress instance.\nThe risk implication is critical, as it bypasses standard access control mechanisms defined within the application, leading to potential full site compromise, unauthorized data access, and the execution of arbitrary administrative actions.\nExploitation does not require sophisticated preconditions beyond an existing authenticated user account, though the specific attack vector involves interacting with the plugin's internal privilege management logic to improperly modify user meta or role-based configurations.\nThe vulnerability underscores a critical failure in the authorization checks performed during privilege-sensitive operations within the plugin's codebase.",
  "technicalDetails": "The vulnerability exists within the LiquidThemes Booking Hub plugin due to insufficient validation and improper authorization controls during user role or privilege management operations.\nThe root cause of this flaw is the plugin's failure to enforce strict 'capability checks' before processing requests that modify user privileges. In many WordPress plugins, administrative functions are expected to utilize current_user_can() to verify if the requesting user possesses the 'manage_options' or similar administrative capabilities.\nThe attack flow begins with an authenticated low-privileged user identifying an endpoint or a process within the Booking Hub plugin that improperly handles privilege assignment. Through the manipulation of specific HTTP request parameters—such as POST variables intended for profile updates or role settings—the attacker submits a request that triggers the vulnerable function.\nBecause the function fails to validate the current user's authority, it blindly processes the input, allowing the attacker to inject or overwrite their existing role metadata with a more privileged role.\nThe vulnerable component involves the logic responsible for updating user profiles or role settings within the Booking Hub plugin. When the plugin processes these requests, it interacts with the WordPress user management API. An insecure implementation of these API calls results in the escalation.\nPost-exploitation, the attacker gains the effective permissions associated with the elevated role. If the attacker escalates to an administrative role, they gain the capability to modify site content, install malicious plugins, create new user accounts, or manipulate existing database records, resulting in complete system compromise.\nThis vulnerability is particularly dangerous because it does not require external network exposure beyond the standard access required to interact with the WordPress dashboard or plugin-specific interfaces. The attack surface is internal to the application's authenticated session, making it a severe threat to multi-user environments where user roles are strictly intended to be compartmentalized.\nThe affected versions range from n/a through 1.3.1. Users operating within this version range are exposed to this risk until appropriate validation patches are applied by the vendor."
}
CVE-2026-81769: Booking Hub Privilege Escalation Vulnerability (HIGH Severity, CVSS: 8.8) - Sceawere