Privilege Escalation via Account Takeover in Booking Package WordPress Plugin
CVE-2026-9851 affects the Booking Package plugin for WordPress in versions up to and including 1.7.16. The flaw is in the 'updateUser' branch of the package_app_action AJAX endpoint. The handler validates only a nonce and does not perform a capability check to ensure the caller is authorized to modify the targeted account. The dispatcher then invokes Schedule::updateUser() with the $administrator argument hard-coded to 1, which bypasses the owner-restriction logic inside that function. As a result, the target user is selected entirely from attacker-controlled input that is passed directly to wp_update_user(). This allows an authenticated attacker with Editor-level privileges or higher to modify arbitrary user accounts, including changing the email address and password of Administrator accounts.
Are you exposed to this one?
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
Impact, mitigation & remediation
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
Impact
What an attacker gets, and what they’ve been doing with it.
Mitigation
If you can’t patch tonight, do this now.
Remediation
Patch, then assume compromise.
Exploits
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Recent activity
6 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
The version that knows your environment.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.