PT-2026-98378 · WordPress · Ba Book Everything

·

CVE-2026-96039

·

Published

2026-09-25

·

Updated

2026-09-25

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions BA Book Everything versions prior to 1.8.28
Description Insufficient input sanitization and output escaping allow unauthenticated attackers to perform Stored Cross-Site Scripting (XSS), a technique where malicious scripts are permanently stored on a target server and executed in the browser of users who visit the affected page. The issue exists in the action to pay() handler via the first name parameter. An attacker can trigger this by placing a guest booking through the [babe-booking-form] shortcode to obtain the necessary order id, order num, and order hash credentials.
Recommendations Update to a version newer than 1.8.27. As a temporary mitigation, restrict access to the action to pay() handler or avoid using the first name parameter in the affected process until the update is applied.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-96039

Affected Products

Ba Book Everything