CVE-2026-32561: WordPress Booking Hub plugin <= 1.3.0 - Privilege Escalation vulnerability
Published Aug 24, 2026
·Updated
Subscriber Privilege Escalation in Booking Hub <= 1.3.0 versions.
Affected Software
1 affected component
WordPress Booking Hub plugin<=1.3.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Booking Hub pluginto a version that resolves this vulnerability.Fixed in 1.3.0
Event History
Aug 24, 2026
CVE Published
via MITRE·09:31 PM
Data Sourced
via MITRE·09:31 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The vulnerability requires low-level privileges. A Subscriber-level account is sufficient to exploit the privilege escalation issue.
2
Can this be exploited remotely without user interaction?
Yes. The vector is network-based, exploitation complexity is low, and no user interaction is required; however, the attacker must first have low-level authenticated access.
3
Which installations are affected?
WordPress sites using the Booking Hub plugin version 1.3.0 or earlier are affected.