{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3awordpressbooking_calendar/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:wordpress:booking_calendar:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-92619"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Booking Calendar (\u003c= 11.8.2)"],"_cs_severities":["high"],"_cs_tags":["privilege-escalation","wordpress","web-application"],"_cs_type":"advisory","_cs_vendors":["WordPress"],"content_html":"\u003cp\u003eThe Booking Calendar plugin for WordPress contains a critical privilege escalation vulnerability, assigned CVE-2026-92619, affecting all versions up to and including 11.8.2. The vulnerability resides in the \u003ccode\u003ewpbc_ajax_option_save\u003c/code\u003e AJAX action, specifically within the \u003ccode\u003ehandle_ajax_save()\u003c/code\u003e function. The plugin fails to validate \u003ccode\u003edata_name\u003c/code\u003e parameters for unregistered options, causing the \u003ccode\u003eget_option_policy()\u003c/code\u003e function to return an empty policy object. This bypasses critical security checks such as \u003ccode\u003ecan_save\u003c/code\u003e, \u003ccode\u003eforce_mode\u003c/code\u003e, and \u003ccode\u003eallowed_keys\u003c/code\u003e. Furthermore, the nonce verification mechanism is flawed, as it accepts attacker-supplied nonce values and actions passed via POST parameters. Attackers can leverage this to modify sensitive WordPress core options - such as \u003ccode\u003edefault_role\u003c/code\u003e and \u003ccode\u003eusers_can_register\u003c/code\u003e - to facilitate the creation of unauthorized Administrator accounts.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker obtains an active session with at least Editor-level privileges on the target WordPress site.\u003c/li\u003e\n\u003cli\u003eAttacker retrieves a valid nonce by requesting \u003ccode\u003eadmin-ajax.php?action=rest-nonce\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a POST request to \u003ccode\u003eadmin-ajax.php\u003c/code\u003e with the action set to \u003ccode\u003ewpbc_ajax_option_save\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eAttacker includes the retrieved nonce in the POST body to bypass the faulty verification check.\u003c/li\u003e\n\u003cli\u003eAttacker provides the \u003ccode\u003edata_name\u003c/code\u003e parameter as \u003ccode\u003edefault_role\u003c/code\u003e and \u003ccode\u003edata_value\u003c/code\u003e as \u003ccode\u003eadministrator\u003c/code\u003e to modify site settings.\u003c/li\u003e\n\u003cli\u003eAttacker sends a second request to update \u003ccode\u003eusers_can_register\u003c/code\u003e to \u003ccode\u003e1\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eAttacker navigates to the standard WordPress registration page and creates a new user account.\u003c/li\u003e\n\u003cli\u003eThe new account is assigned the Administrator role due to the modified site settings.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in full administrative control over the WordPress instance. This allows for unauthorized data access, complete site compromise, and the ability to execute further malicious actions within the affected environment. The flaw affects any installation of the Booking Calendar plugin versions 11.8.2 and earlier.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for security teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately upgrade the Booking Calendar plugin to version 11.8.3 or later, where the security policy checks have been hardened.\u003c/li\u003e\n\u003cli\u003eAudit the \u003ccode\u003ewp_options\u003c/code\u003e table in the database for unexpected modifications to \u003ccode\u003edefault_role\u003c/code\u003e or \u003ccode\u003eusers_can_register\u003c/code\u003e settings.\u003c/li\u003e\n\u003cli\u003eReview user accounts created or modified within the audit timeframe to identify unauthorized administrative access.\u003c/li\u003e\n\u003cli\u003eEnable Web Application Firewall (WAF) logging for POST requests to \u003ccode\u003eadmin-ajax.php\u003c/code\u003e to monitor for unusual \u003ccode\u003ewpbc_ajax_option_save\u003c/code\u003e payloads.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-18T08:04:44Z","date_published":"2026-09-18T08:04:44Z","id":"https://feed.craftedsignal.io/briefs/2026-09-booking-calendar-privilege-escalation/","summary":"The Booking Calendar plugin for WordPress is vulnerable to privilege escalation (CVE-2026-92619) allowing authenticated Editors to modify arbitrary site settings and create administrative accounts.","title":"Booking Calendar Plugin Privilege Escalation via AJAX Parameter Injection","url":"https://feed.craftedsignal.io/briefs/2026-09-booking-calendar-privilege-escalation/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:wordpress:booking_calendar:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}