{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aba_book_everythingba_book_everything/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:ba_book_everything:ba_book_everything:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-102565"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["BA Book Everything (\u003c= 1.8.28)"],"_cs_severities":["high"],"_cs_tags":["web-application","xss","wordpress"],"_cs_type":"advisory","_cs_vendors":["BA Book Everything"],"content_html":"\u003cp\u003eThe BA Book Everything plugin for WordPress, in all versions up to and including 1.8.28, is vulnerable to a Stored Cross-Site Scripting (XSS) attack. This vulnerability stems from insufficient input sanitization and output escaping of the 'booking_service_qty' parameter. An unauthenticated attacker can supply a malicious script payload through this parameter during the booking process. The script is then stored by the plugin and executed within the browser of an administrator or privileged user when they view the compromised order record within the WordPress dashboard. This vulnerability poses a significant risk as it allows for unauthorized actions performed under the context of an authenticated session, potentially leading to administrative account compromise or further internal exploitation.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies the target WordPress site using the BA Book Everything plugin.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious JavaScript payload intended for execution in an admin's browser.\u003c/li\u003e\n\u003cli\u003eAttacker initiates a booking request and sends a crafted POST request containing the script in the 'booking_service_qty' parameter.\u003c/li\u003e\n\u003cli\u003eThe plugin fails to sanitize the input and stores the malicious script in the WordPress database associated with the order.\u003c/li\u003e\n\u003cli\u003eAn administrator logs into the WordPress wp-admin dashboard to manage or review incoming orders.\u003c/li\u003e\n\u003cli\u003eThe administrator accesses the compromised order record via the plugin's order management interface.\u003c/li\u003e\n\u003cli\u003eThe browser renders the stored order details, triggering the execution of the attacker's script in the context of the administrator's authenticated session.\u003c/li\u003e\n\u003cli\u003eThe attacker achieves their objective, such as creating a new admin user, exfiltrating session tokens, or modifying site configuration.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in the execution of arbitrary code within the administrator's browser session. Given that the payload is viewed in the wp-admin management area, the attacker can hijack active sessions, perform administrative tasks, or inject further malicious content into the WordPress site, potentially affecting site integrity and the security of all registered users.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized, concrete actions for detection engineering and security teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the BA Book Everything plugin to version 1.8.29 or the latest available patched version immediately.\u003c/li\u003e\n\u003cli\u003eAudit existing order records within the plugin for suspicious scripts, specifically looking for common HTML/JavaScript tags (e.g., \u0026lt;script\u0026gt;, onerror, onload) in numeric fields.\u003c/li\u003e\n\u003cli\u003eMonitor webserver logs for POST requests to the booking endpoint containing non-numeric characters within the 'booking_service_qty' parameter.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-02T08:23:04Z","date_published":"2026-10-02T08:23:04Z","id":"https://feed.craftedsignal.io/briefs/2026-10-ba-book-everything-xss/","summary":"The BA Book Everything plugin for WordPress contains a Stored XSS vulnerability in the booking_service_qty parameter, allowing unauthenticated attackers to execute arbitrary scripts in the context of an administrator.","title":"Stored Cross-Site Scripting in BA Book Everything Plugin","url":"https://feed.craftedsignal.io/briefs/2026-10-ba-book-everything-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:ba_book_everything:ba_book_everything:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}