Impact
The WP Hotel Booking plugin contains a reflected Cross‑Site Scripting flaw triggered by the unchecked 'check_in_date' query parameter. When an attacker crafts a URL containing malicious code, the unsanitized value is echoed back into the page, allowing the execution of arbitrary JavaScript in the victim's browser. This can lead to cookie theft, session hijacking, phishing payloads or site defacement without requiring any privileged access.
Affected Systems
All WordPress sites that have installed ThimPress WP Hotel Booking plugin versions up to and including 2.3.2 are affected. Any instance of the plugin in those releases will expose the reflected XSS vulnerability.
Risk and Exploitability
The vulnerability scores a CVSS of 6.1, indicating moderate severity. The EPSS score of less than 1% suggests that exploitation is not common at present and the issue is not listed in the CISA KEV catalog. Attackers can succeed simply by luring a user to a malicious link; no authentication or elevated privileges are required. While the probability of exploitation is low, a successful payload would compromise user confidentiality and integrity, making it a meaningful risk.
OpenCVE Enrichment