Impact
The WP BASE Booking plugin includes a subscriber cross‑site scripting flaw that allows a malicious actor who can submit booking data to inject JavaScript code that will execute in the browsers of other users who view the affected content. This can lead to data theft, session hijacking, or other browser‑based attacks. The weakness is caused by inadequate escaping of user input.
Affected Systems
The vulnerability is present in the WordPress WP BASE Booking plugin supplied by Hakan Ozevin, affecting all released versions up to and including 6.3.2.
Risk and Exploitability
The CVSS base score is 6.5, indicating a moderate severity level. EPSS information is not available, so the current exploitation likelihood is unknown. The vulnerability is not listed in CISA KEV. The likely attack vector is a web‑based posting of malicious payloads by a subscriber; the flaw can be triggered without elevated privileges and remains active until the plugin is patched or input is properly sanitized.
OpenCVE Enrichment