Junglewise Threat Intelligence

CVE-2026-73402: WP BASE Booking cross-site scripting in subscriber actions

CVE-2026-73402 · Severity: medium · CVSS 6.5 · Published 2026-08-20

Technologies: WP BASE Booking. Vendors: WP BASE Booking.

Executive brief

WP BASE Booking is a popular WordPress plugin for managing appointment and event bookings. A cross-site scripting vulnerability allows attackers with subscriber-level access to inject malicious scripts that can steal visitor data or hijack user accounts. The vulnerability affects all versions up to 6.3.2 and is fixed in version 6.4.0.

Technical details

This is a stored or reflected cross-site scripting (XSS) vulnerability in WP BASE Booking plugin versions 6.3.2 and earlier. The vulnerability requires subscriber-level privileges and user interaction (such as clicking a malicious link or visiting a crafted page) to be successfully exploited. An attacker with subscriber access can inject malicious JavaScript that executes in the browser context of other users, potentially allowing session hijacking, credential theft, or malware distribution. The vulnerability is fixed in version 6.4.0; users should upgrade immediately.

Affected products

  • WP BASE Booking WP BASE Booking ≤ 6.3.2

Timeline

  • 2026-08-20: disclosed
  • 2026-08-20: patched: Fixed in version 6.4.0

References

Related threats