{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/ba-book-everything--1.8.27/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-96039"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["BA Book Everything (\u003c= 1.8.27)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eThe BA Book Everything plugin for WordPress, versions 1.8.27 and earlier, is vulnerable to a Stored Cross-Site Scripting (XSS) attack via the first_name parameter. The vulnerability arises from insufficient input sanitization and output escaping of data submitted through the booking process. An unauthenticated attacker can exploit this by placing a guest booking via the public [babe-booking-form] shortcode, which provides the necessary parameters (order_id, order_num, order_hash) to reach the vulnerable action_to_pay() handler. Successful exploitation allows for the execution of arbitrary JavaScript in the context of a user session when they access the affected page. This vulnerability presents a significant risk for session hijacking and unauthorized data access within WordPress environments using this plugin.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker navigates to the public page containing the [babe-booking-form] shortcode.\u003c/li\u003e\n\u003cli\u003eAttacker initiates a guest booking flow, which generates a valid order_id, order_num, and order_hash.\u003c/li\u003e\n\u003cli\u003eAttacker submits the booking form while injecting a malicious payload into the first_name parameter.\u003c/li\u003e\n\u003cli\u003eThe application processes the request, invoking the action_to_pay() handler.\u003c/li\u003e\n\u003cli\u003eThe server stores the malicious JavaScript payload in the database without proper sanitization.\u003c/li\u003e\n\u003cli\u003eAn administrative or other user visits the page where the stored booking information is rendered.\u003c/li\u003e\n\u003cli\u003eThe user's browser executes the injected JavaScript payload, potentially leading to unauthorized actions or data exfiltration.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to execute arbitrary web scripts in the browser of users viewing the booking information. This can result in session hijacking, administrative account compromise, and unauthorized access to sensitive booking data, impacting any WordPress site utilizing the affected version of the BA Book Everything plugin.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the BA Book Everything plugin to a version released after 1.8.27 to mitigate CVE-2026-96039.\u003c/li\u003e\n\u003cli\u003eAudit access logs for high-frequency booking form submissions that include non-standard characters (like \u0026lt;script\u0026gt; or alert()) in the first_name field.\u003c/li\u003e\n\u003cli\u003eMonitor webserver access logs for POST requests to the plugin's booking handler followed by subsequent requests to the order payment or detail pages.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-25T08:55:39Z","date_published":"2026-09-25T08:55:39Z","id":"https://feed.craftedsignal.io/briefs/2026-09-ba-book-everything-xss/","summary":"The BA Book Everything WordPress plugin contains a stored XSS vulnerability in the first_name parameter, allowing unauthenticated attackers to inject arbitrary scripts.","title":"CVE-2026-96039 Stored XSS in BA Book Everything WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-09-ba-book-everything-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - BA Book Everything (\u003c= 1.8.27)","version":"https://jsonfeed.org/version/1.1"}