CVE-2026-28161: WordPress Service Finder Booking plugin <= 6.2 - Privilege Escalation vulnerability
Published Aug 13, 2026
·Updated
Subscriber Privilege Escalation in Service Finder Booking <= 6.2 versions.
Affected Software
1 affected component
WordPress Service Finder Booking<=6.2
Event History
Aug 13, 2026
CVE Published
via MITRE·01:36 PM
Data Sourced
via MITRE·01:36 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-28161?
CVE-2026-28161 has a high severity rating of 8.8.
2
What type of vulnerability is CVE-2026-28161?
CVE-2026-28161 is a privilege escalation vulnerability affecting the WordPress Service Finder Booking plugin.
3
How do I fix CVE-2026-28161?
To fix CVE-2026-28161, update the WordPress Service Finder Booking plugin to version 6.3 or later.
4
What versions of the plugin are affected by CVE-2026-28161?
CVE-2026-28161 affects versions of the WordPress Service Finder Booking plugin up to and including 6.2.
5
What impact does CVE-2026-28161 have on users?
CVE-2026-28161 allows unauthorized users to escalate their privileges to a higher access level.