Stored Cross-Site Scripting in BA Book Everything Plugin
The BA Book Everything plugin for WordPress contains a Stored XSS vulnerability in the booking_service_qty parameter, allowing unauthenticated attackers to execute arbitrary scripts in the context of an administrator.
CVE search metadata
CVE search record: CVE-2026-102565. Severity: high. CVSS: 7.2. KEV: no. Product: BA Book Everything (<= 1.8.28). Brief: Stored Cross-Site Scripting in BA Book Everything Plugin. Brief link: https://feed.craftedsignal.io/briefs/2026-10-ba-book-everything-xss/
The BA Book Everything plugin for WordPress, in all versions up to and including 1.8.28, is vulnerable to a Stored Cross-Site Scripting (XSS) attack. This vulnerability stems from insufficient input sanitization and output escaping of the 'booking_service_qty' parameter. An unauthenticated attacker can supply a malicious script payload through this parameter during the booking process. The script is then stored by the plugin and executed within the browser of an administrator or privileged user when they view the compromised order record within the WordPress dashboard. This vulnerability poses a significant risk as it allows for unauthorized actions performed under the context of an authenticated session, potentially leading to administrative account compromise or further internal exploitation.
Attack Chain
- Attacker identifies the target WordPress site using the BA Book Everything plugin.
- Attacker crafts a malicious JavaScript payload intended for execution in an admin's browser.
- Attacker initiates a booking request and sends a crafted POST request containing the script in the 'booking_service_qty' parameter.
- The plugin fails to sanitize the input and stores the malicious script in the WordPress database associated with the order.
- An administrator logs into the WordPress wp-admin dashboard to manage or review incoming orders.
- The administrator accesses the compromised order record via the plugin's order management interface.
- The browser renders the stored order details, triggering the execution of the attacker's script in the context of the administrator's authenticated session.
- The attacker achieves their objective, such as creating a new admin user, exfiltrating session tokens, or modifying site configuration.
Impact
Successful exploitation results in the execution of arbitrary code within the administrator's browser session. Given that the payload is viewed in the wp-admin management area, the attacker can hijack active sessions, perform administrative tasks, or inject further malicious content into the WordPress site, potentially affecting site integrity and the security of all registered users.
Recommendation
Prioritized, concrete actions for detection engineering and security teams:
- Update the BA Book Everything plugin to version 1.8.29 or the latest available patched version immediately.
- Audit existing order records within the plugin for suspicious scripts, specifically looking for common HTML/JavaScript tags (e.g., <script>, onerror, onload) in numeric fields.
- Monitor webserver logs for POST requests to the booking endpoint containing non-numeric characters within the 'booking_service_qty' parameter.
Immediate actions
Update BA Book Everything plugin to version 1.8.29 or newer.
Threat Hunt
Search database for scripts stored in booking_service_qty column.
Data: WordPress database table contents
Mitigations
Patch plugin.
CVE-2026-102565
Detection coverage 1
Detects CVE-2026-102565 Exploitation - Stored XSS in BA Book Everything
highDetects attempted exploitation of CVE-2026-102565 by identifying suspicious characters or script tags in the booking_service_qty parameter within POST requests.
Detection queries are available on the platform. Get full rules →