What the vulnerability does
01Description
Unauthenticated Arbitrary Code Execution in WP BASE Booking <= 6.3.0 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
What the vulnerability does
Unauthenticated Arbitrary Code Execution in WP BASE Booking <= 6.3.0 versions.
Explanation of Vulnerability in Simple Terms
WP BASE Booking versions up to 6.3.0 contain a code injection vulnerability that allows unauthenticated attackers to run arbitrary PHP code on the site without user interaction. The vulnerability stems from improper handling of user input, enabling remote code execution with full system access. All installations should update immediately.
What an attacker can do
Run arbitrary PHP code on the site and take complete control of it.
Potential impact on your site
Complete compromise of the WordPress site, including data theft, malware installation, and site defacement.
Conditions required to exploit
Network access only; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities