Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
10.0

CVE-2026-61962: WP BASE Booking versions <= 6.3.0 allow hackers to run code

CVE-2026-61962 · published 22 days ago
Summary

The WP BASE Booking plugin has a security issue that allows an attacker to execute malicious code on your website without needing a password. This could lead to unauthorized access, data theft, or other malicious activities. To protect your website, update the plugin to a version higher than 6.3.0.

What to do
  • Update hakan ozevin wp base booking to version 6.3.1.
Affected software
VendorProductAffected versions
hakan ozevin wp base booking <= 6.3.0
Fix: upgrade to 6.3.1
Original advisory text
WordPress WP BASE Booking plugin <= 6.3.0 - Arbitrary Code Execution vulnerability
Unauthenticated Arbitrary Code Execution in WP BASE Booking <= 6.3.0 versions.
Severity
10.0 Critical
CVSS 3.1: 10.0 (NVD)
Exploitation
EPSS <1%
Type
CWE-94Code Injection
Timeline
Published13 Aug 2026
Updated3 Sep 2026
First seen13 Aug 2026
Sources
CVE-2026-61962 · MITRE
Monitor software like this
Free during beta