PT-2026-57048 · WordPress · Wp Hotel Booking
CVE-2026-11392
·
Published
2026-07-10
·
Updated
2026-07-10
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
WP Hotel Booking versions prior to 2.3.2
Description
Insufficient input sanitization and output escaping allow unauthenticated attackers to perform Reflected Cross-Site Scripting. This occurs when attackers trick users into clicking a link containing malicious scripts injected via the
check in date and check out date parameters.Recommendations
Update to a version newer than 2.3.1.
Avoid using the
check in date and check out date parameters until the plugin is updated.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wp Hotel Booking