PatchSiren

LiquidThemes CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH LiquidThemes CVE published 2026-09-02

CVE-2026-81769

The CVE-2026-81769 record describes an Incorrect Privilege Assignment vulnerability in LiquidThemes Booking Hub, which allows for Privilege Escalation. This issue affects Booking Hub versions from n/a through 1.3.1. The CVSS score is 8.8, indicating a HIGH severity. The CVE record was published on 2026-09-02T12:17:12.913Z and was last modified on 2026-09-04T03:17:42.463Z.

HIGH LiquidThemes CVE published 2025-12-16

CVE-2025-68065

CVE-2025-68065 is a high-severity PHP local file inclusion issue in Hub Core, affecting versions before 6.0.2. The published record describes improper control of a filename used in an include/require path, with NVD classifying the weakness as CWE-98. Site owners should treat this as a serious exposure risk for unpatched WordPress installations running the plugin.