Stored Cross-Site Scripting Vulnerability in BA Book Everything Plugin by WordPress
CVE-2026-102565
7.2HIGH
What is CVE-2026-102565?
The BA Book Everything plugin for WordPress is susceptible to a Stored Cross-Site Scripting vulnerability triggered by the 'booking_service_qty' parameter. This issue arises from inadequate input sanitization and output escaping mechanisms currently present in the plugin. As a result, unauthenticated attackers can introduce malicious web scripts into pages that execute upon user access. Exploiting this vulnerability necessitates that an administrator or another privileged user accesses the compromised order record within the plugin's wp-admin order management interface, following the usual order-review processes.
Affected Version(s)
BA Book Everything 0 <= 1.8.28