Impact
The vulnerability stems from improper neutralization of user-supplied input during page generation, enabling DOM-based Cross‑Site Scripting. An attacker can inject malicious JavaScript that executes in the browser of anyone who views the affected page, potentially leading to cookie theft, session hijacking, defacement, or other client‑side attacks. This weakness is classified as CWE‑79.
Affected Systems
WordPress Easy Hotel Booking plugin Easy Hotel Booking (by themewant) version 1.9.0 and earlier. Any WordPress site that has the plugin installed and has not upgraded beyond that release is susceptible.
Risk and Exploitability
The vulnerability carries a CVSS score of 6.5, indicating moderate severity, and an EPSS score of less than 1 %, suggesting a low probability of exploitation. It is not listed in the CISA KEV catalog. The likely attack vector is web‑based, requiring an adversary to embed a malicious payload in the plugin’s input fields or URLs that trick a user’s browser into executing the injected script.
OpenCVE Enrichment
EUVD