Unauthenticated Code Execution Vulnerability in WP BASE Booking Plugin
CVE-2026-61962

10CRITICAL

Key Information:

Vendor

WordPress

Vendor
CVE Published:
13 August 2026

What is CVE-2026-61962?

A vulnerability exists in the WP BASE Booking plugin that allows unauthenticated users to execute arbitrary code. This issue affects all versions up to 6.3.0, potentially compromising the security of the WordPress site. Proper measures should be taken to secure the plugin and ensure that the latest patched versions are installed to mitigate potential risks.

Affected Version(s)

WP BASE Booking <= 6.3.0

References

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

buitu | Patchstack Bug Bounty Program
.