Impact
Booking Manager allows improper neutralization of input during web page generation, creating a stored XSS condition. Malicious code injected through any user‑controlled field is persisted and executed in the browsers of all users who view the affected pages, enabling session hijacking, defacement, or phishing attacks.
Affected Systems
WordPress sites that install the Booking Manager plugin from wpdevelop, specifically any release up to and including version 2.1.18.
Risk and Exploitability
The CVSS score of 6.5 classifies this flaw as moderate severity. The EPSS score is not available and the vulnerability has not been listed in CISA KEV, yet the plugin’s widespread adoption suggests a non‑negligible attack surface. Exploitation requires only a malicious payload entered into a plugin form; because the payload is stored, it is rendered for every page view, making the attack highly effective once the input is submitted.
OpenCVE Enrichment