CVE-2026-96039: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in bookingalgorithms BA Book Everything
The BA Book Everything plugin for WordPress is vulnerable to Stored Cross-Site Scripting via first_name Parameter in all versions up to, and including, 1.8.27 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. An unauthenticated attacker can obtain the valid order_id, order_num, and order_hash credentials required to reach the vulnerable action_to_pay() handler simply by placing a guest booking through the public [babe-booking-form] shortcode, making the full exploit chain reachable without any account.
AI Analysis
Technical Summary
CVE-2026-96039 describes a stored cross-site scripting vulnerability (CWE-79) in the BA Book Everything plugin for WordPress. The vulnerability arises from insufficient input sanitization and output escaping of the first_name parameter in versions up to 1.8.27. An unauthenticated attacker can place a guest booking using the public shortcode to obtain valid order credentials (order_id, order_num, order_hash) required to reach the vulnerable action_to_pay() handler. This enables injection of arbitrary web scripts that execute whenever a user views the affected pages.
Potential Impact
Successful exploitation allows an unauthenticated attacker to inject and execute arbitrary scripts in the context of the affected website, potentially leading to information disclosure and user session compromise. The CVSS 3.1 score is 7.2 (high severity) with network attack vector, low attack complexity, no privileges required, no user interaction, and impacts on confidentiality and integrity with scope changed.
Mitigation Recommendations
No patch or official fix is currently provided in the available data. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, users should consider disabling the plugin or restricting access to the booking form shortcode to trusted users only to mitigate exploitation risk.
CVE-2026-96039: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in bookingalgorithms BA Book Everything
Description
The BA Book Everything plugin for WordPress is vulnerable to Stored Cross-Site Scripting via first_name Parameter in all versions up to, and including, 1.8.27 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. An unauthenticated attacker can obtain the valid order_id, order_num, and order_hash credentials required to reach the vulnerable action_to_pay() handler simply by placing a guest booking through the public [babe-booking-form] shortcode, making the full exploit chain reachable without any account.
CVSS v3.1
Score 7.2high
Affected software
bookingalgorithms
BA Book Everything
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-96039 describes a stored cross-site scripting vulnerability (CWE-79) in the BA Book Everything plugin for WordPress. The vulnerability arises from insufficient input sanitization and output escaping of the first_name parameter in versions up to 1.8.27. An unauthenticated attacker can place a guest booking using the public shortcode to obtain valid order credentials (order_id, order_num, order_hash) required to reach the vulnerable action_to_pay() handler. This enables injection of arbitrary web scripts that execute whenever a user views the affected pages.
Potential Impact
Successful exploitation allows an unauthenticated attacker to inject and execute arbitrary scripts in the context of the affected website, potentially leading to information disclosure and user session compromise. The CVSS 3.1 score is 7.2 (high severity) with network attack vector, low attack complexity, no privileges required, no user interaction, and impacts on confidentiality and integrity with scope changed.
Mitigation Recommendations
No patch or official fix is currently provided in the available data. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, users should consider disabling the plugin or restricting access to the booking form shortcode to trusted users only to mitigate exploitation risk.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- Wordfence
- Date Reserved
- 2026-09-22T18:00:49.665Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6ab61cb7f7a7c5410676d534
Added to database: 09/25/2026, 07:03:19 UTC
Last enriched: 09/25/2026, 07:17:38 UTC
Last updated: 09/26/2026, 02:48:44 UTC
Views: 21
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.