๐Ÿ” CVE Alert

CVE-2026-92619

HIGH 7.2

Booking Calendar <= 11.8.2 - Authenticated (Editor+) Privilege Escalation to 'data_name' Parameter

CVSS Score
7.2
EPSS Score
0.0%
EPSS Percentile
0th

The Booking Calendar plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 11.8.2 via the `wpbc_ajax_option_save` AJAX action. The vulnerability exists because the `handle_ajax_save()` function applies per-option safeguards only to names explicitly registered via `register_option_policy()`, causing `get_option_policy()` to return an empty policy โ€” bypassing all can_save, force_mode, and allowed_keys checks โ€” for any unregistered option name, including core WordPress options, while an attacker-controlled `data_name` parameter passes through `sanitize_key()` and is written directly to `update_option()` without restriction. This makes it possible for authenticated attackers with Editor-level access and above to escalate their privileges to Administrator by writing core WordPress options such as `default_role=administrator` and `users_can_register=1`, then self-registering a new Administrator account. The nonce check does not meaningfully restrict this attack, as both the nonce value and nonce action are attacker-supplied POST parameters, and a valid nonce is trivially obtainable via `admin-ajax.php?action=rest-nonce`.

CWE CWE-269
Vendor wpdevelop
Product booking calendar
Published Sep 18, 2026
Stay Ahead of the Next One

Get instant alerts for wpdevelop booking calendar

Be the first to know when new high vulnerabilities affecting wpdevelop booking calendar are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

wpdevelop / Booking Calendar
0 โ‰ค 11.8.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wordfence.com: https://www.wordfence.com/threat-intel/vulnerabilities/id/ab68a6b2-e9b0-4efa-bd01-c6e3e11011db?source=cve plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/booking/tags/11.8.2/includes/save-load-option/save-load-option.php#L303 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/booking/tags/11.8.2/includes/save-load-option/save-load-option.php#L197 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/booking/tags/11.8.2/includes/save-load-option/save-load-option.php#L138 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/booking/tags/11.8.2/includes/page-form-builder/ajax/bfb-ajax.php#L82 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/changeset?reponame=&old=3699185%40booking&new=3699185%40booking

Credits

Wordfence PRISM