[ARCHIVE]2026-06-06T06:00:28.595036+00:00
CVE-2026-9851
Executive Summary
The Booking Package plugin for WordPress is vulnerable to Privilege Escalation via Account Takeover in versions up to, and including, 1.7.16. This is due to a missing capability check on the 'updateUser' branch of the packageappaction AJAX endpoint, where the handler only validates a nonce and the d...
Deep analysis unavailable for this source.
View Original SourceClassification: Open