HIGH
bookingalgorithms
CVE published 2026-09-25
CVE-2026-96039
The BA Book Everything plugin for WordPress has a Stored Cross-Site Scripting vulnerability via the first_name parameter in versions up to and including 1.8.27. This allows unauthenticated attackers to inject web scripts that execute when a user accesses an injected page. The exploit chain is reachable without an account by obtaining valid order credentials through a guest booking.