
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-67953 is an Incorrect Privilege Assignment vulnerability in the Booking Activities WordPress plugin (by Booking Activities Team) that allows unauthenticated remote attackers to escalate privileges. It affects all versions of the plugin through and including 1.16.44, with version 1.16.45 being the patched release. The vulnerability was reported on November 7, 2025, published by Patchstack on January 20–22, 2026, and assigned a CVSS v3.1 base score of 8.1 (High) by CISA-ADP (Patchstack, NVD).
The vulnerability is classified as CWE-266 (Incorrect Privilege Assignment), meaning the plugin incorrectly assigns or validates privilege levels during certain operations, enabling an attacker to obtain elevated permissions without proper authorization. The attack vector is network-based, requires no authentication or user interaction, and carries high attack complexity. The flaw was discovered by researcher "daroo" and reported through Patchstack's coordinated disclosure process (Patchstack). No public proof-of-concept code has been disclosed at this time.
Successful exploitation could allow an unauthenticated attacker to escalate their privileges on the affected WordPress site, potentially gaining administrative or high-privilege access. This could result in full website takeover, unauthorized access to sensitive data, modification of site content or configuration, and potential denial of service. The confidentiality, integrity, and availability impacts are all rated High (Patchstack).
Patchstack classifies this vulnerability as "Known to be exploited" (KEV) and notes it is expected to be used in mass-exploit campaigns targeting thousands of WordPress sites regardless of traffic or popularity. The EPSS score is approximately 0.017% (0.000170), indicating a currently low but non-zero probability of exploitation in the wild. No public proof-of-concept exploit has been confirmed, and no specific threat actor attribution is available (Patchstack, Feedly).
The vulnerability is patched in Booking Activities version 1.16.45; all users running version 1.16.44 or earlier should update immediately. Patchstack has also issued a virtual patching/mitigation rule for its subscribers to block exploitation attempts until the plugin is updated. If an immediate update is not possible, consider disabling the plugin or implementing network-level access controls to restrict unauthorized access, and monitor WordPress access logs for suspicious privilege escalation activity (Patchstack).
Wordfence included CVE-2025-67953 in its weekly WordPress vulnerability report for the week of January 19–25, 2026, highlighting it as a notable privilege escalation issue in the WordPress plugin ecosystem (Wordfence). Red Packet Security also referenced it in a CISA vulnerability summary for the same week (Red Packet Security). No significant broader media coverage or notable researcher commentary beyond these routine aggregations has been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."