PT-2026-98378 · WordPress · Ba Book Everything
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
BA Book Everything versions prior to 1.8.28
Description
Insufficient input sanitization and output escaping allow unauthenticated attackers to perform Stored Cross-Site Scripting (XSS), a technique where malicious scripts are permanently stored on a target server and executed in the browser of users who visit the affected page. The issue exists in the
action to pay() handler via the first name parameter. An attacker can trigger this by placing a guest booking through the [babe-booking-form] shortcode to obtain the necessary order id, order num, and order hash credentials.Recommendations
Update to a version newer than 1.8.27.
As a temporary mitigation, restrict access to the
action to pay() handler or avoid using the first name parameter in the affected process until the update is applied.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ba Book Everything