Description
The BA Book Everything plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's babe-search-form shortcode in all versions up to, and including, 1.8.14 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Published: 2025-12-19
Score: 6.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting exploitable by authenticated users with contributor or higher role
Action: Update Plugin
AI Analysis

Impact

The BA Book Everything plugin is vulnerable to a stored cross‑site scripting flaw triggered through its babe‑search‑form shortcode. Insufficient sanitization and escaping of user‑supplied attributes allows an attacker who can add or edit content to insert arbitrary JavaScript into pages. When a victim loads the injected page, the script runs in the victim’s browser, potentially stealing credentials, session data, or defacing the site. The weakness corresponds to CWE‑79, a classic reflected/encoded script injection.

Affected Systems

WordPress sites that have installed any version of the BA Book Everything plugin up to and including 1.8.14. Site owners who have granted contributor or higher permissions to users are at risk, as the attacker only needs such access to inject the malicious payload.

Risk and Exploitability

The CVSS score of 6.4 indicates medium severity, and the EPSS score of less than 1% suggests a very low probability of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog. Attackers can exploit it remotely by submitting a crafted URL or shortcode from a contributor account; the payload is stored within the plugin’s database and executed only when a page containing the shortcode is rendered to another user.

Generated by OpenCVE AI on April 22, 2026 at 16:03 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the BA Book Everything plugin to a version newer than 1.8.14 that contains the input validation and output escaping fix
  • If an upgrade is not immediately possible, restrict the use of the babe‑search‑form shortcode to administrators only and remove or sanitize any existing instances from content
  • Install a reputable web‑application firewall or security plugin that blocks or sanitizes suspicious JavaScript embedded in page content

Generated by OpenCVE AI on April 22, 2026 at 16:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 21 Dec 2025 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Booking Algorithms
Booking Algorithms ba Book Everything
Wordpress
Wordpress wordpress
Vendors & Products Booking Algorithms
Booking Algorithms ba Book Everything
Wordpress
Wordpress wordpress

Fri, 19 Dec 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 19 Dec 2025 07:00:00 +0000

Type Values Removed Values Added
Description The BA Book Everything plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's babe-search-form shortcode in all versions up to, and including, 1.8.14 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Title BA Book Everything <= 1.8.14 - Authenticated (Contributor+) Stored Cross-Site Scripting via babe-search-form Shortcode
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

Booking Algorithms Ba Book Everything
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-04-08T16:43:45.109Z

Reserved: 2025-12-10T14:11:04.227Z

Link: CVE-2025-14449

cve-icon Vulnrichment

Updated: 2025-12-19T18:45:35.811Z

cve-icon NVD

Status : Deferred

Published: 2025-12-19T07:16:01.420

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-14449

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-22T16:15:21Z

Weaknesses