Impact
Unauthenticated Cross Site Scripting (XSS) is present in the Hotel Booking WordPress plugin versions up to 3.8. The flaw allows an attacker to inject arbitrary JavaScript that executes in the browsers of anyone who visits the compromised pages. This can lead to theft of session cookies, defacement, or other malicious actions in the context of the logged‑in user. The weakness is a classic reflected XSS flaw (CWE‑79).
Affected Systems
The affected product is the WordPress plugin Nicdark Hotel Booking, specifically all releases up to and including 3.8. Any WordPress site running one of these versions is susceptible. No other vendors or software are listed.
Risk and Exploitability
The CVSS score of 7.1 indicates a moderate severity level. The exploit probability ( the data, and the vulnerability is not listed in CISA's KEV catalog. Because the issue is unauthenticated, an attacker only needs to send a crafted request containing malicious payloads. The likely attack path is through web forms or query parameters accepted by the plugin without proper sanitization. At present, there are no known public exploits. Site operators should consider the mitigations below.
OpenCVE Enrichment