CVE-2026-9851
Description
The Booking Package plugin for WordPress is vulnerable to Privilege Escalation via Account Takeover in versions up to, and including, 1.7.16. This is due to a missing capability check on the 'updateUser' branch of the package_app_action AJAX endpoint, where the handler only validates a nonce and the dispatcher invokes Schedule::updateUser() with the $administrator argument hard-coded to 1, bypassing the only owner-restriction check inside that function and allowing the target user to be determined solely by attacker-supplied input passed directly to wp_update_user(). This makes it possible for authenticated attackers, with Editor-level access and above, to change the email address and password of any account, including Administrator accounts, resulting in a full site takeover.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2<=1.7.16+ 1 more
- (no CPE)range: <=1.7.16
- (no CPE)range: <=1.7.16
Patches
Vulnerability mechanics
References
5- plugins.trac.wordpress.org/browser/booking-package/tags/1.7.13/index.phpnvd
- plugins.trac.wordpress.org/browser/booking-package/tags/1.7.13/index.phpnvd
- plugins.trac.wordpress.org/browser/booking-package/tags/1.7.13/lib/Schedule.phpnvd
- plugins.trac.wordpress.org/changesetnvd
- www.wordfence.com/threat-intel/vulnerabilities/id/795c1fd6-137b-4414-8d6b-30053bfb5924nvd
News mentions
1- Wordfence Intelligence Weekly WordPress Vulnerability Report (June 1, 2026 to June 7, 2026)Wordfence Blog · Jun 11, 2026