CVE-2026-73402: WordPress WP BASE Booking plugin <= 6.3.2 - Cross Site Scripting (XSS) vulnerability
Published Aug 20, 2026
·Updated
Subscriber Cross Site Scripting (XSS) in WP BASE Booking <= 6.3.2 versions.
Affected Software
1 affected component
WP BASE Booking<=6.3.2
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress WP BASE Booking pluginto a version that resolves this vulnerability.Fixed in 6.4.0
Event History
Aug 20, 2026
CVE Published
via MITRE·12:07 PM
Data Sourced
via MITRE·12:07 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The vulnerability is exploitable by a subscriber-level user, so an attacker needs an account with subscriber permissions.
2
Does exploitation require victim interaction?
Yes. The CVSS vector indicates user interaction is required, meaning a victim must interact with attacker-controlled content for the XSS payload to execute.
3
Can this be exploited remotely?
Yes. The network attack vector indicates the issue can be reached remotely, provided the attacker has the required subscriber-level access.