CVE-2026-61962

10.0

Hakan Ozevin · WP BASE Booking

The WP BASE Booking plugin for WordPress contains an unauthenticated arbitrary code execution vulnerability, allowing remote attackers to execute malicious code on the host server.

Executive summary

A critical unauthenticated arbitrary code execution vulnerability in the WP BASE Booking plugin poses a severe risk of total system compromise.

Vulnerability

This vulnerability is a code injection flaw, identified as CWE-94, which allows unauthenticated remote attackers to execute arbitrary code. The vulnerability exists due to improper control over the generation of code within the plugin, requiring no user interaction or elevated privileges to exploit.

Business impact

The CVSS score of 10.0 reflects the maximum severity of this vulnerability, as it allows for complete unauthorized control over the affected server. Successful exploitation could lead to full data theft, permanent system damage, or the deployment of ransomware, resulting in significant operational downtime and potential regulatory penalties.

Remediation

Immediate Action: Update the WP BASE Booking plugin to version 6.3.1 or the latest available version immediately.

Proactive Monitoring: Monitor server access logs for unusual requests directed at the plugin directory and examine system logs for unexpected process execution.

Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to detect and block malicious injection attempts targeting WordPress plugin parameters.

Exploitation status

Public Exploit Available: No

Analyst recommendation

This vulnerability represents a critical security risk due to the lack of required authentication and the potential for total system takeover. All organizations utilizing the WP BASE Booking plugin must apply the vendor provided update immediately to mitigate the risk of remote code execution.

More Hakan Ozevin CVEs