CVE-2026-61962: Unauthenticated Arbitrary Code Execution in WP BASE Booking Plugin
A critical vulnerability (CVE-2026-61962) with a CVSS score of 10 has been discovered in the WP BASE Booking plugin (versions <= 6.3.0). This unauthenticated arbitrary code execution vulnerability allows attackers to execute code remotely without authentication, posing a significant risk to WordPress installations using this plugin. Immediate patching is recommended to prevent potential exploitation.