CVE-2026-61962Patch

LOWCVSS 10.0 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Unauthenticated Arbitrary Code Execution in WP BASE Booking <= 6.3.0 versions.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-08-13: 1Patch / Workaround · 2026-08-13: 1Technical Details · 2026-08-13: 108-13
Signal classification1 categories
Patch
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • SecAlerts@SecAlertsCo
    Patch

    📅 WP BASE Booking plugin &lt;=6.3.0: unauthenticated arbitrary code execution, CVSS 10. No login needed to run code on your site. CVE-2026-61962 — update or remove now. #cybersecurity #wordpress #vulnerabilities #ciso #mssp https://secalerts.co/vulnerability/CVE-2026-61962?utm_campaign=x https://t.co/6uZqGBMlhX

    Post summary

    The tweet announces CVE-2026-61962, highlighting an unauthenticated arbitrary code execution flaw (CVSS 10) in WP BASE Booking plugin and urges users to update or remove to mitigate the risk.

    00010206
    877 followersView on X

Explore more