Impact
The BA Book Everything WordPress plugin allows untrusted input supplied via the 'booking_service_qty' parameter to be stored without proper sanitization or escaping, enabling a stored Cross‑Site Scripting (XSS) vulnerability. An attacker can inject malicious JavaScript, which will execute whenever a privileged user opens the corresponding order record in the admin order‑management interface. This could lead to session hijacking, credential theft, or the execution of arbitrary code with the administrative privileges of the site owner.
Affected Systems
All versions of the BA Book Everything plugin up to and including 1.8.28 are affected. The vulnerability exists in WordPress sites that have the plugin installed and in use for booking orders.
Risk and Exploitability
The CVSS score of 7.2 indicates a high severity level, and although the EPSS score is not available, the lack of a KEV listing does not diminish the need for remediation. The attack vector is unauthenticated, but exploitation requires that a privileged or administrator user subsequently access the injected record, meaning that the threat is contingent on administrative interaction but can be triggered by any unauthenticated actor who can create the vulnerable order entry.
OpenCVE Enrichment