<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>BA Book Everything (&lt;= 1.8.28) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/ba-book-everything--1.8.28/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 02 Oct 2026 08:23:04 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/ba-book-everything--1.8.28/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Stored Cross-Site Scripting in BA Book Everything Plugin</title><link>https://feed.craftedsignal.io/briefs/2026-10-ba-book-everything-xss/</link><pubDate>Fri, 02 Oct 2026 08:23:04 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-ba-book-everything-xss/</guid><description>The BA Book Everything plugin for WordPress contains a Stored XSS vulnerability in the booking_service_qty parameter, allowing unauthenticated attackers to execute arbitrary scripts in the context of an administrator.</description><content:encoded><![CDATA[<p>The BA Book Everything plugin for WordPress, in all versions up to and including 1.8.28, is vulnerable to a Stored Cross-Site Scripting (XSS) attack. This vulnerability stems from insufficient input sanitization and output escaping of the 'booking_service_qty' parameter. An unauthenticated attacker can supply a malicious script payload through this parameter during the booking process. The script is then stored by the plugin and executed within the browser of an administrator or privileged user when they view the compromised order record within the WordPress dashboard. This vulnerability poses a significant risk as it allows for unauthorized actions performed under the context of an authenticated session, potentially leading to administrative account compromise or further internal exploitation.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker identifies the target WordPress site using the BA Book Everything plugin.</li>
<li>Attacker crafts a malicious JavaScript payload intended for execution in an admin's browser.</li>
<li>Attacker initiates a booking request and sends a crafted POST request containing the script in the 'booking_service_qty' parameter.</li>
<li>The plugin fails to sanitize the input and stores the malicious script in the WordPress database associated with the order.</li>
<li>An administrator logs into the WordPress wp-admin dashboard to manage or review incoming orders.</li>
<li>The administrator accesses the compromised order record via the plugin's order management interface.</li>
<li>The browser renders the stored order details, triggering the execution of the attacker's script in the context of the administrator's authenticated session.</li>
<li>The attacker achieves their objective, such as creating a new admin user, exfiltrating session tokens, or modifying site configuration.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation results in the execution of arbitrary code within the administrator's browser session. Given that the payload is viewed in the wp-admin management area, the attacker can hijack active sessions, perform administrative tasks, or inject further malicious content into the WordPress site, potentially affecting site integrity and the security of all registered users.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritized, concrete actions for detection engineering and security teams:</p>
<ul>
<li>Update the BA Book Everything plugin to version 1.8.29 or the latest available patched version immediately.</li>
<li>Audit existing order records within the plugin for suspicious scripts, specifically looking for common HTML/JavaScript tags (e.g., &lt;script&gt;, onerror, onload) in numeric fields.</li>
<li>Monitor webserver logs for POST requests to the booking endpoint containing non-numeric characters within the 'booking_service_qty' parameter.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>web-application</category><category>xss</category><category>wordpress</category></item></channel></rss>