Sceawere

Vulnerability Detail

CVE-2026-102565UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

BA Book Everything Stored XSS

Vulnerability Metadata

Severity
High
Score / CVSS
7.2
Creation Date
16h ago
Vendor
bookingalgorithms
Product
BA Book Everything
Attack Type
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

The BA Book Everything plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'booking_service_qty' parameter in all versions up to, and including, 1.8.28 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Successful exploitation requires that an administrator or other privileged user opens the injected order record in the plugin's wp-admin order management area, which is the plugin's ordinary order-review workflow.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.2",
  "pubDate": "2026-10-02T07:16:35.617Z",
  "pubdate": "2026-10-02T07:16:35.617Z",
  "executiveSummary": "The BA Book Everything WordPress plugin is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability due to improper input sanitization and output escaping within the 'booking_service_qty' parameter.\nThis vulnerability allows unauthenticated attackers to inject malicious JavaScript payloads into booking records. The injected scripts are stored server-side and executed within the context of an administrator's browser session when they access the affected record in the plugin's wp-admin dashboard.\nSuccessful exploitation facilitates unauthorized script execution, which can lead to administrative session hijacking, credential theft, or unauthorized actions performed on behalf of the privileged user.\nThe vulnerability affects all versions of the BA Book Everything plugin up to and including 1.8.28.\nThis flaw presents a significant security risk, as it leverages the standard administrative workflow to execute payloads, bypassing typical perimeter security measures.",
  "technicalDetails": "The root cause of this vulnerability is the failure of the 'booking_service_qty' parameter to undergo adequate input validation and sanitization prior to database storage, coupled with a lack of proper output encoding when rendering the data in the WordPress administrative interface.\nThe vulnerability exists within the plugin's booking request handling logic. An unauthenticated attacker can craft a malicious HTTP request targeting the plugin's booking functionality, embedding arbitrary JavaScript code within the 'booking_service_qty' parameter. Because the application processes this input without sanitizing or encoding, the malicious payload is persisted in the database associated with the booking order.\nThe exploitation flow is as follows: 1. An attacker initiates a booking request and injects a script payload into the 'booking_service_qty' field. 2. The plugin saves this record to the database without filtering the input. 3. An administrator navigates to the 'wp-admin' order management area of the BA Book Everything plugin. 4. Upon the administrator opening the compromised order record, the application retrieves the malicious string from the database and renders it directly into the HTML context of the administrator's page. 5. The browser interprets and executes the embedded script within the administrator's session, granting the attacker the ability to perform actions with the victim's privileges.\nThe vulnerability is characterized as Stored XSS because the payload is persistently stored on the server. The impact is significant, as administrative users often hold high-privilege credentials. Execution in this context allows the attacker to potentially manipulate plugin settings, create new administrative users, or exfiltrate sensitive data available within the wp-admin panel.\nThe primary requirement for exploitation is the interaction of a privileged user with the corrupted order record. No specific authentication is required from the attacker, allowing external actors to stage the exploit effectively.\nThe vulnerable component is the processing logic for booking metadata, specifically where user-supplied inputs are mapped to backend order fields and subsequently displayed in administrative views without applying output escaping functions such as esc_html() or esc_js()."
}
CVE-2026-102565: BA Book Everything Stored XSS (HIGH Severity, CVSS: 7.2) | Sceawere