CVE-2026-61962 CRITICAL

CVE-2026-61962: WordPress WP BASE Booking plugin <= 6.3.0 - Arbitrary Code Execution vulnerability

Vendor Hakan Ozevin
Product WP BASE Booking
Weakness CWE-94 · Code injection
Published August 13, 2026
Last update August 13, 2026

CVSS base score

10.0/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

What the vulnerability does

01Description

Unauthenticated Arbitrary Code Execution in WP BASE Booking <= 6.3.0 versions.

Explanation of Vulnerability in Simple Terms

02Summary

WP BASE Booking versions up to 6.3.0 contain a code injection vulnerability that allows unauthenticated attackers to run arbitrary PHP code on the site without user interaction. The vulnerability stems from improper handling of user input, enabling remote code execution with full system access. All installations should update immediately.

What an attacker can do

03Attacker Capabilities

Run arbitrary PHP code on the site and take complete control of it.

Potential impact on your site

04Site Impact

Complete compromise of the WordPress site, including data theft, malware installation, and site defacement.

Conditions required to exploit

05Prerequisites

Network access only; no authentication or user interaction required.

Key dates

06Disclosure timeline

August 13, 2026 CVE published

Related vulnerabilities

08Related CVE