CVE-2026-61962
10.0Hakan Ozevin · WP BASE Booking
The WP BASE Booking plugin for WordPress contains an unauthenticated arbitrary code execution vulnerability, allowing remote attackers to execute malicious code on the host server.
Executive summary
A critical unauthenticated arbitrary code execution vulnerability in the WP BASE Booking plugin poses a severe risk of total system compromise.
Vulnerability
This vulnerability is a code injection flaw, identified as CWE-94, which allows unauthenticated remote attackers to execute arbitrary code. The vulnerability exists due to improper control over the generation of code within the plugin, requiring no user interaction or elevated privileges to exploit.
Business impact
The CVSS score of 10.0 reflects the maximum severity of this vulnerability, as it allows for complete unauthorized control over the affected server. Successful exploitation could lead to full data theft, permanent system damage, or the deployment of ransomware, resulting in significant operational downtime and potential regulatory penalties.
Remediation
Immediate Action: Update the WP BASE Booking plugin to version 6.3.1 or the latest available version immediately.
Proactive Monitoring: Monitor server access logs for unusual requests directed at the plugin directory and examine system logs for unexpected process execution.
Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to detect and block malicious injection attempts targeting WordPress plugin parameters.
Exploitation status
Public Exploit Available: No
Analyst recommendation
This vulnerability represents a critical security risk due to the lack of required authentication and the potential for total system takeover. All organizations utilizing the WP BASE Booking plugin must apply the vendor provided update immediately to mitigate the risk of remote code execution.