CVE-2026-96039 | BookingAlgorithms BA Book Everything Plugin up to 1.8.27 on WordPress Shortcode action_to_pay first_name cross site scripting

SecurityVulns

A vulnerability was found in BookingAlgorithms BA Book Everything Plugin up to 1.8.27 on WordPress. It has been classified as problematic. The affected element is the function action_to_pay of the component Shortcode Handler. This manipulation of the argument first_name causes cross site scripting.

This vulnerability is registered as CVE-2026-96039. Remote exploitation of the attack is possible. No exploit is available.VulDB Recent EntriesRead More