Impact
This vulnerability arises from improper neutralization of input during web page generation in the Booking and Rental Manager plugin. Because the plugin stores user‑supplied data without adequate filtering, an attacker can embed malicious JavaScript that will later be rendered within the plugin’s pages. The result is stored cross‑site scripting, allowing attackers to execute arbitrary scripts in the browsers of visitors who view affected content, potentially leading to session hijacking, defacement, or the delivery of further malware.
Affected Systems
The flaw exists in all releases of the Booking and Rental Manager plugin up to and including version 2.7.7, supplied by Magepeople inc. Users running any earlier version are also impacted. Current releases after 2.7.8 contain the fix.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity impact. The EPSS score is not reported, and the vulnerability is not part of the CISA KEV list, implying lower current exploitation activity. The likely attack vector requires the attacker to inject malicious input through the plugin’s data entry interfaces, potentially through an authenticated or compromised account. Once the malicious payload is stored, it will be delivered to any user who views the injected content, making the vulnerability highly damaging if the attacker gains access to the site’s content management.
OpenCVE Enrichment