PT-2026-95278 · Wpdevelop · Booking Calendar
CVSS v3.1
7.2
Alta
| Vetor | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
The Booking Calendar plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 11.8.2 via the
wpbc ajax option save AJAX action. The vulnerability exists because the handle ajax save() function applies per-option safeguards only to names explicitly registered via register option policy(), causing get option policy() to return an empty policy — bypassing all can save, force mode, and allowed keys checks — for any unregistered option name, including core WordPress options, while an attacker-controlled data name parameter passes through sanitize key() and is written directly to update option() without restriction. This makes it possible for authenticated attackers with Editor-level access and above to escalate their privileges to Administrator by writing core WordPress options such as default role=administrator and users can register=1, then self-registering a new Administrator account. The nonce check does not meaningfully restrict this attack, as both the nonce value and nonce action are attacker-supplied POST parameters, and a valid nonce is trivially obtainable via admin-ajax.php?action=rest-nonce.Correção
Improper Privilege Management
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Booking Calendar