CVE-2026-102565

CVE-2026-102565 published: The BA Book Everything plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'booking_service_qty' parameter in all versions up to, and including, 1.8.28 due to insufficient input sanitization and output escaping. This makes it possible ...

View full NVD advisory → ← Back to CVE watch