CPE
The BA Book Everything plugin for WordPress contains a Stored XSS vulnerability in the booking_service_qty parameter, allowing unauthenticated attackers to execute arbitrary scripts in the context of an administrator.