CVE-2026-92619 PUBLISHED

Booking Calendar <= 11.8.2 - Authenticated (Editor+) Privilege Escalation to 'data_name' Parameter

Assigner: Wordfence
Reserved: 16.09.2026 Published: 18.09.2026 Updated: 18.09.2026

The Booking Calendar plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 11.8.2 via the wpbc_ajax_option_save AJAX action. The vulnerability exists because the handle_ajax_save() function applies per-option safeguards only to names explicitly registered via register_option_policy(), causing get_option_policy() to return an empty policy — bypassing all can_save, force_mode, and allowed_keys checks — for any unregistered option name, including core WordPress options, while an attacker-controlled data_name parameter passes through sanitize_key() and is written directly to update_option() without restriction. This makes it possible for authenticated attackers with Editor-level access and above to escalate their privileges to Administrator by writing core WordPress options such as default_role=administrator and users_can_register=1, then self-registering a new Administrator account. The nonce check does not meaningfully restrict this attack, as both the nonce value and nonce action are attacker-supplied POST parameters, and a valid nonce is trivially obtainable via admin-ajax.php?action=rest-nonce.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 7.2

Product Status

Vendor wpdevelop
Product Booking Calendar
Versions Default: unaffected
  • affected from 0 to 11.8.2 (incl.)

Credits

  • Wordfence PRISM finder

References

Problem Types

  • CWE-269 Improper Privilege Management CWE