Description
Unauthenticated Cross Site Scripting (XSS) in Hotel Booking <= 3.8 versions.
Published: 2026-10-06
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Cross Site Scripting (XSS)
Action: Patch
AI Analysis

Impact

Unauthenticated Cross Site Scripting (XSS) is present in the Hotel Booking WordPress plugin versions up to 3.8. The flaw allows an attacker to inject arbitrary JavaScript that executes in the browsers of anyone who visits the compromised pages. This can lead to theft of session cookies, defacement, or other malicious actions in the context of the logged‑in user. The weakness is a classic reflected XSS flaw (CWE‑79).

Affected Systems

The affected product is the WordPress plugin Nicdark Hotel Booking, specifically all releases up to and including 3.8. Any WordPress site running one of these versions is susceptible. No other vendors or software are listed.

Risk and Exploitability

The CVSS score of 7.1 indicates a moderate severity level. The exploit probability ( the data, and the vulnerability is not listed in CISA's KEV catalog. Because the issue is unauthenticated, an attacker only needs to send a crafted request containing malicious payloads. The likely attack path is through web forms or query parameters accepted by the plugin without proper sanitization. At present, there are no known public exploits. Site operators should consider the mitigations below.

Generated by OpenCVE AI on October 6, 2026 at 11:14 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Hotel Booking plugin to the latest version that removes the XSS flaw.
  • If an upgrade is not possible immediately, restrict input by applying a web application firewall rule set that blocks common XSS payloads (e.g., ModSecurity OWASP core rule set).
  • Disable or sanitize any plugin features that allow unescaped user input, such as booking form fields or review submissions.

Generated by OpenCVE AI on October 6, 2026 at 11:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 06 Oct 2026 09:00:00 +0000

Type Values Removed Values Added
Description Unauthenticated Cross Site Scripting (XSS) in Hotel Booking <= 3.8 versions.
Title WordPress Hotel Booking plugin <= 3.8 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-06T10:31:34.555Z

Reserved: 2026-04-07T10:59:15.736Z

Link: CVE-2026-39784

cve-icon Vulnrichment

Updated: 2026-10-06T10:29:32.315Z

cve-icon NVD

Status : Received

Published: 2026-10-06T09:17:50.940

Modified: 2026-10-06T11:17:25.480

Link: CVE-2026-39784

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T11:15:18Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')