CVE-2025-67953: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-67953 is an Incorrect Privilege Assignment vulnerability in the Booking Activities WordPress plugin (by Booking Activities Team) that allows unauthenticated remote attackers to escalate privileges. It affects all versions of the plugin through and including 1.16.44, with version 1.16.45 being the patched release. The vulnerability was reported on November 7, 2025, published by Patchstack on January 20–22, 2026, and assigned a CVSS v3.1 base score of 8.1 (High) by CISA-ADP (Patchstack, NVD).

Technical details

The vulnerability is classified as CWE-266 (Incorrect Privilege Assignment), meaning the plugin incorrectly assigns or validates privilege levels during certain operations, enabling an attacker to obtain elevated permissions without proper authorization. The attack vector is network-based, requires no authentication or user interaction, and carries high attack complexity. The flaw was discovered by researcher "daroo" and reported through Patchstack's coordinated disclosure process (Patchstack). No public proof-of-concept code has been disclosed at this time.

Impact

Successful exploitation could allow an unauthenticated attacker to escalate their privileges on the affected WordPress site, potentially gaining administrative or high-privilege access. This could result in full website takeover, unauthorized access to sensitive data, modification of site content or configuration, and potential denial of service. The confidentiality, integrity, and availability impacts are all rated High (Patchstack).

Exploitability

Patchstack classifies this vulnerability as "Known to be exploited" (KEV) and notes it is expected to be used in mass-exploit campaigns targeting thousands of WordPress sites regardless of traffic or popularity. The EPSS score is approximately 0.017% (0.000170), indicating a currently low but non-zero probability of exploitation in the wild. No public proof-of-concept exploit has been confirmed, and no specific threat actor attribution is available (Patchstack, Feedly).

Mitigation and workarounds

The vulnerability is patched in Booking Activities version 1.16.45; all users running version 1.16.44 or earlier should update immediately. Patchstack has also issued a virtual patching/mitigation rule for its subscribers to block exploitation attempts until the plugin is updated. If an immediate update is not possible, consider disabling the plugin or implementing network-level access controls to restrict unauthorized access, and monitor WordPress access logs for suspicious privilege escalation activity (Patchstack).

Community reactions

Wordfence included CVE-2025-67953 in its weekly WordPress vulnerability report for the week of January 19–25, 2026, highlighting it as a notable privilege escalation issue in the WordPress plugin ecosystem (Wordfence). Red Packet Security also referenced it in a CISA vulnerability summary for the same week (Red Packet Security). No significant broader media coverage or notable researcher commentary beyond these routine aggregations has been identified.

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management