Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in xtreeme Planyo online reservation system planyo-online-reservation-system allows Stored XSS.This issue affects Planyo online reservation system: from n/a through <= 3.1.
Published: 2025-04-01
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a classic Stored Cross‑Site Scripting flaw caused by improper neutralization of input during web page generation in the xtreeme Planyo online reservation system. Malicious data placed into the system’s storage is later rendered in a web response without adequate escaping, so an attacker can inject JavaScript that runs in the browser of anyone who views the affected page. This can lead to session hijacking, theft of credentials, defacement, and lateral movement within the site. The weakness falls under CWE‑79 – Improper Neutralization of Input During Web Page Generation.

Affected Systems

The flaw affects the WordPress plugin "Planyo online reservation system" developed by xtreeme. All releases from the initial version through 3.1 inclusive are impacted. Sites running the plugin with any of these versions are vulnerable, regardless of other WordPress components.

Risk and Exploitability

The CVSS base score of 6.5 indicates a moderate level of risk, while the EPSS score of less than 1 % suggests a low probability of exploitation in the short term. The vulnerability is not listed in the CISA KEV catalog. Because the flaw requires the attacker to inject payload into a data field that is later rendered on a page, it is likely to be exploited by users with permission to add or edit reservation content, or via social engineering to trick an authorized user into submitting malicious input. If exploited, the impact can be significant due to the potential for persistent script execution across sessions.

Generated by OpenCVE AI on May 1, 2026 at 02:03 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to the newest release of the Planyo online reservation system plugin that contains the patch for the stored XSS flaw.
  • If an upgrade is not immediately possible, restrict who can submit data to the plugin’s storage fields, enforce strict server‑side validation and output encoding for any user‑supplied content, and review user roles to limit exposure.
  • Deploy a Content Security Policy that disallows inline scripts and restricts script sources, thereby mitigating the impact of any remaining unpatched XSS vectors.

Generated by OpenCVE AI on May 1, 2026 at 02:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-9226 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in xtreeme Planyo online reservation system allows Stored XSS. This issue affects Planyo online reservation system: from n/a through 3.0.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in xtreeme Planyo online reservation system allows Stored XSS. This issue affects Planyo online reservation system: from n/a through 3.0. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in xtreeme Planyo online reservation system planyo-online-reservation-system allows Stored XSS.This issue affects Planyo online reservation system: from n/a through <= 3.1.
Title WordPress Planyo online reservation system plugin <= 3.0 - Cross Site Scripting (XSS) vulnerability WordPress Planyo online reservation system plugin <= 3.1 - Cross Site Scripting (XSS) vulnerability
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Tue, 01 Apr 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 01 Apr 2025 15:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in xtreeme Planyo online reservation system allows Stored XSS. This issue affects Planyo online reservation system: from n/a through 3.0.
Title WordPress Planyo online reservation system plugin <= 3.0 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:13.240Z

Reserved: 2025-04-01T13:20:24.606Z

Link: CVE-2025-31811

cve-icon Vulnrichment

Updated: 2025-04-01T18:25:51.744Z

cve-icon NVD

Status : Deferred

Published: 2025-04-01T15:16:20.750

Modified: 2026-04-23T15:28:20.520

Link: CVE-2025-31811

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T02:15:06Z

Weaknesses