Stored Cross-Site Scripting Vulnerability in BA Book Everything Plugin by WordPress
CVE-2026-102565

7.2HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
2 October 2026

What is CVE-2026-102565?

The BA Book Everything plugin for WordPress is susceptible to a Stored Cross-Site Scripting vulnerability triggered by the 'booking_service_qty' parameter. This issue arises from inadequate input sanitization and output escaping mechanisms currently present in the plugin. As a result, unauthenticated attackers can introduce malicious web scripts into pages that execute upon user access. Exploiting this vulnerability necessitates that an administrator or another privileged user accesses the compromised order record within the plugin's wp-admin order management interface, following the usual order-review processes.

Affected Version(s)

BA Book Everything 0 <= 1.8.28

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

crow
.