Executive brief
The BA Book Everything plugin for WordPress contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts into booking pages. When site visitors access pages containing the injected scripts, the malicious code executes in their browsers, potentially stealing session data, credentials, or performing actions on their behalf. Attackers can exploit this through the public booking form without needing any account or special permissions.
Technical details
The vulnerability exists in the action_to_pay() handler due to insufficient input sanitization on the first_name parameter. Unauthenticated attackers can obtain valid order credentials (order_id, order_num, order_hash) by placing a guest booking through the public [babe-booking-form] shortcode, then inject arbitrary web scripts that are stored and executed when other users access the affected pages. The flaw affects versions up to and including 1.8.27.
Affected products
- Code Red Pixels BA Book Everything up to and including 1.8.27
Timeline
- 2026-09-25: disclosed