PatchSiren

bookingalgorithms CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH bookingalgorithms CVE published 2026-09-25

CVE-2026-96039

The BA Book Everything plugin for WordPress has a Stored Cross-Site Scripting vulnerability via the first_name parameter in versions up to and including 1.8.27. This allows unauthenticated attackers to inject web scripts that execute when a user accesses an injected page. The exploit chain is reachable without an account by obtaining valid order credentials through a guest booking.