Impact
The vulnerability is an improper neutralization of input during web page generation, which results in stored cross‑site scripting (XSS) within the Deetronix Booking Ultra Pro plugin. By injecting malicious JavaScript into the plugin’s input fields, an attacker can cause the script to execute in the browsers of anyone who views the affected page. The impact is primarily client‑side code injection that can lead to session hijacking, cookie theft, defacement, or phishing attacks against site visitors.
Affected Systems
WordPress sites that employ the Deetronix Booking Ultra Pro plugin are affected. All plugin releases from the initial version up to and including 1.1.21 are vulnerable. Sites running any of those versions should be considered at risk.
Risk and Exploitability
The CVSS score of 6.5 indicates a medium‑to‑high severity. The EPSS score of less than 1% suggests that exploitation attempts are currently rare, and the vulnerability is not listed in the CISA KEV catalog, implying no confirmed widespread exploitation. The most likely attack vector is through normal or admin‑level interaction with the plugin’s input forms, enabling an attacker to store malicious code that later runs in visitors’ browsers. No public exploits have been reported at the time of this analysis.
OpenCVE Enrichment
EUVD