Impact
Deetronix Booking Ultra Pro contains an Improper Neutralization of Input During Web Page Generation flaw that allows attackers to store malicious scripts in the plugin’s data. The stored XSS is triggered when users or administrators view pages rendered by the plugin, potentially exposing all visitors to harmful JavaScript. This type of weakness can compromise confidentiality, integrity, and availability by enabling session hijacking, data theft, or site defacement.
Affected Systems
The vulnerability affects the Booking Ultra Pro WordPress plugin version 1.1.20 and earlier. Sites running the plugin with any of these versions are vulnerable, regardless of other WordPress components.
Risk and Exploitability
The CVSS score of 5.9 indicates a medium severity impact. The EPSS score of <1% shows the current likelihood of exploitation is low, and the vulnerability is not listed in CISA’s KEV catalogue. The attack vector can be inferred as stored input through plugin fields that are not properly sanitized, meaning that any user able to submit data via those fields—such as an administrator or an unprivileged contributor—could inject the payload. Once executed in a victim’s browser, the XSS can provide the attacker with arbitrary client‑side control.
OpenCVE Enrichment
EUVD