Impact
The Hostel plugin for WordPress contains a stored cross‑site scripting flaw in the 'wphostel-book' shortcode. The plugin fails to sanitize the second attribute, which is stored and later output directly into an HTML value attribute. This omission allows an authenticated attacker with at least Contributor privileges to embed malicious JavaScript that will execute in the browsers of any user who views the affected page, providing the attacker with the ability to run arbitrary scripts.
Affected Systems
All WordPress sites running the Hostel plugin by prasunsen with a version equal to or earlier than 1.1.7 are affected. The vulnerability applies to any environment where the plugin is installed and activated.
Risk and Exploitability
The flaw carries a CVSS score of 6.4, indicating moderate severity, while the EPSS score of less than 1% reflects a very low current exploitation probability. The vulnerability is not listed in CISA's KEV catalog. Attackers must be authenticated with Contributor or higher privileges and must inject a malicious payload via the shortcode. Once stored, the script executes automatically for any user viewing the affected page, creating a persistent XSS risk.
OpenCVE Enrichment