Impact
The Turisbook Booking System plugin for WordPress contains a stored XSS flaw caused by improper input neutralization during page generation. Malicious code injected into stored data is later rendered in a visitor’s browser, potentially allowing attackers to steal session cookies, deface content, or run arbitrary scripts. The weakness is classified as CWE‑79 and compromises user data integrity and confidentiality.
Affected Systems
The vulnerability affects the Neteuro Turisbook Booking System plug‑in for WordPress versions from the earliest released iteration through 1.3.8. Users who have deployed any version up to and including 1.3.8 are impacted.
Risk and Exploitability
With a CVSS score of 6.5 the flaw has moderate severity, and an EPSS score of less than 1% suggests a low likelihood of widespread exploitation at present, though the vulnerability is not listed in CISA KEV. The likely attack path is via web‑based input fields that store data (such as booking forms or comments); an attacker injecting script payloads that are subsequently rendered for all users is sufficient to exploit the flaw. Providers who cannot update immediately face a moderate risk, as any user with access to a stored entry containing the malicious payload will execute the script.
OpenCVE Enrichment
EUVD