Description
The BA Book Everything plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'booking_service_qty' parameter in all versions up to, and including, 1.8.28 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Successful exploitation requires that an administrator or other privileged user opens the injected order record in the plugin's wp-admin order management area, which is the plugin's ordinary order-review workflow.
Published: 2026-10-02
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross-Site Scripting
Action: Apply Patch
AI Analysis

Impact

The BA Book Everything WordPress plugin allows untrusted input supplied via the 'booking_service_qty' parameter to be stored without proper sanitization or escaping, enabling a stored Cross‑Site Scripting (XSS) vulnerability. An attacker can inject malicious JavaScript, which will execute whenever a privileged user opens the corresponding order record in the admin order‑management interface. This could lead to session hijacking, credential theft, or the execution of arbitrary code with the administrative privileges of the site owner.

Affected Systems

All versions of the BA Book Everything plugin up to and including 1.8.28 are affected. The vulnerability exists in WordPress sites that have the plugin installed and in use for booking orders.

Risk and Exploitability

The CVSS score of 7.2 indicates a high severity level, and although the EPSS score is not available, the lack of a KEV listing does not diminish the need for remediation. The attack vector is unauthenticated, but exploitation requires that a privileged or administrator user subsequently access the injected record, meaning that the threat is contingent on administrative interaction but can be triggered by any unauthenticated actor who can create the vulnerable order entry.

Generated by OpenCVE AI on October 2, 2026 at 08:54 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the BA Book Everything plugin to version 1.8.29 or later.
  • If an update is not yet available, remove or disable the 'booking_service_qty' parameter from the order creation process to prevent any unsanitized input from being stored.
  • Sanitize any existing order records in the database and ensure that all output, particularly in the admin order‑management area, is properly escaped to prevent XSS execution.

Generated by OpenCVE AI on October 2, 2026 at 08:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 07:15:00 +0000

Type Values Removed Values Added
Description The BA Book Everything plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'booking_service_qty' parameter in all versions up to, and including, 1.8.28 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Successful exploitation requires that an administrator or other privileged user opens the injected order record in the plugin's wp-admin order management area, which is the plugin's ordinary order-review workflow.
Title BA Book Everything <= 1.8.28 - Unauthenticated Stored Cross-Site Scripting via 'booking_service_qty' Parameter
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-02T06:38:59.015Z

Reserved: 2026-09-29T13:33:21.907Z

Link: CVE-2026-102565

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-02T07:16:35.617

Modified: 2026-10-02T13:18:55.613

Link: CVE-2026-102565

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T09:00:18Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')