Impact
The vulnerability is an improper neutralization of input that permits an attacker to store malicious scripts in pages generated by the Hakan Ozevin WP BASE Booking plugin. Because the plugin encodes output incorrectly, attacker supplied content is later rendered without sanitization, which can execute arbitrary JavaScript in the browsers of any user who visits the affected pages. This flaw is a classic Stored XSS, identified by CWE‑79, and it can lead to session hijacking, data theft, or defacement of the site. The type of weakness is input validation and output encoding failure.
Affected Systems
The affected software is the WordPress plugin Hakan Ozevin WP BASE Booking, in all releases up to and including version 5.0.0. No additional vendor or product variants are listed, and the version range extends from the earliest release through 5.0.0.
Risk and Exploitability
The CVSS score of 7.1 indicates a high potential impact. The EPSS score is listed as < 1 %, signifying a very low but non‑zero likelihood of exploitation in the wild. The vulnerability is not included in CISA’s KEV catalog, implying that no documented, large‑scale attacks are currently known. The most likely attack path is an adversary inserting malicious script through an interface of the plugin that accepts user input—such as booking forms or administrative content fields—where the data is later stored and displayed to users without proper sanitization.
OpenCVE Enrichment
EUVD