CVE-2026-81769: WordPress Booking Hub plugin <= 1.3.1 - Privilege Escalation vulnerability
Published Sep 2, 2026
·Updated
Subscriber Privilege Escalation in Booking Hub <= 1.3.1 versions.
Affected Software
1 affected component
WordPress Booking Hub<=1.3.1
Event History
Sep 2, 2026
CVE Published
via MITRE·11:37 AM
Data Sourced
via MITRE·11:37 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The vulnerability requires subscriber-level privileges. It does not require user interaction and can be exploited over the network.
2
What is the potential impact if the vulnerability is exploited?
An attacker could escalate privileges, with high impact to confidentiality, integrity, and availability according to the supplied CVSS vector.
3
Which plugin versions are affected?
Booking Hub versions 1.3.1 and earlier are identified as affected.