CVE-2026-61962: WordPress WP BASE Booking plugin <= 6.3.0 - Arbitrary Code Execution vulnerability
Published Aug 13, 2026
·Updated
Unauthenticated Arbitrary Code Execution in WP BASE Booking <= 6.3.0 versions.
Affected Software
1 affected component
wordpress/WP BASE Booking<=6.3.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress WP BASE Booking Pluginto a version that resolves this vulnerability.Fixed in 6.3.1
Event History
Aug 13, 2026
CVE Published
via MITRE·01:36 PM
Data Sourced
via MITRE·01:36 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-61962?
CVE-2026-61962 has a critical severity rating of 10.
2
How do I fix CVE-2026-61962?
To fix CVE-2026-61962, update the WP BASE Booking plugin to version 6.3.1 or later.
3
What type of vulnerability is CVE-2026-61962?
CVE-2026-61962 is classified as an Arbitrary Code Execution vulnerability.
4
Who is affected by CVE-2026-61962?
CVE-2026-61962 affects users of WP BASE Booking plugin versions 6.3.0 and earlier.
5
What are the potential impacts of CVE-2026-61962?
CVE-2026-61962 can allow unauthenticated attackers to execute arbitrary code on the affected WordPress installations.