PT-2026-65782 · WordPress · Trafft

·

CVE-2026-8791

·

Published

2026-07-29

·

Updated

2026-07-29

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Booking System Trafft versions prior to 1.0.18
Description Stored Cross-Site Scripting occurs when the plugin operates in agency mode due to a missing capability check on the set options AJAX action. The trafftSetOptions() handler verifies a nonce available to any authenticated user but fails to verify permissions before calling update option() to modify the bookingWebsiteUrl setting. Subsequently, the trafftAdminAssets() function enqueues a script from the bookingWebsiteUrl on every front-end page rendering the booking shortcode. This allows authenticated users with Subscriber-level access or higher to redirect the script source to an attacker-controlled origin and execute arbitrary JavaScript in the browsers of all site visitors, including administrators.
Recommendations Update to a version newer than 1.0.17.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-8791

Affected Products

Trafft