Back to FeedIntel Vault / Permanent Record
[ARCHIVE]2026-06-06T06:00:28.595036+00:00
CVE-2026-9851

CVE-2026-9851

Executive Summary

The Booking Package plugin for WordPress is vulnerable to Privilege Escalation via Account Takeover in versions up to, and including, 1.7.16. This is due to a missing capability check on the 'updateUser' branch of the packageappaction AJAX endpoint, where the handler only validates a nonce and the d...

Deep analysis unavailable for this source.

View Original SourceClassification: Open