Impact
An input sanitization flaw in the Bob Hostel WordPress plugin allows an attacker to inject arbitrary JavaScript that is executed in the context of a user’s browser when a crafted URL or form is visited. Based on the description, the attack vector is inferred to be web-based: an attacker must trick a victim into visiting a crafted URL or submitting a malicious form. This reflected XSS can lead to credential theft, session hijack, and defacement of the site. The vulnerability is rooted in improper neutralization of user input before rendering it as part of a web page and is classified as CWE‑79.
Affected Systems
Any WordPress site that has the Bob Hostel plugin installed with a version up to and including 1.1.5.9 is affected. The issue was present from the plugin’s earliest releases (“n/a”) through version 1.1.5.9. Owners of these installations are therefore vulnerable until they update the plugin.
Risk and Exploitability
The current CVSS score is 7.1, indicating a high impact if exploited. The EPSS score is less than 1%, suggesting a low probability of exploitation at the present time. The vulnerability is not listed in the CISA KEV catalog. Typical exploitation would involve an attacker crafting a malicious URL or form input that is reflected back to the victim’s browser; the attack vector is web-based and requires the victim to visit a targeted page or submit a form containing malicious content.
OpenCVE Enrichment