Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Magepeople inc. Booking and Rental Manager allows Stored XSS.

This issue affects Booking and Rental Manager: from n/a through 2.7.7.
Published: 2026-09-03
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability arises from improper neutralization of input during web page generation in the Booking and Rental Manager plugin. Because the plugin stores user‑supplied data without adequate filtering, an attacker can embed malicious JavaScript that will later be rendered within the plugin’s pages. The result is stored cross‑site scripting, allowing attackers to execute arbitrary scripts in the browsers of visitors who view affected content, potentially leading to session hijacking, defacement, or the delivery of further malware.

Affected Systems

The flaw exists in all releases of the Booking and Rental Manager plugin up to and including version 2.7.7, supplied by Magepeople inc. Users running any earlier version are also impacted. Current releases after 2.7.8 contain the fix.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate severity impact. The EPSS score is not reported, and the vulnerability is not part of the CISA KEV list, implying lower current exploitation activity. The likely attack vector requires the attacker to inject malicious input through the plugin’s data entry interfaces, potentially through an authenticated or compromised account. Once the malicious payload is stored, it will be delivered to any user who views the injected content, making the vulnerability highly damaging if the attacker gains access to the site’s content management.

Generated by OpenCVE AI on September 3, 2026 at 20:28 UTC.

Remediation

Vendor Solution

Update the WordPress Booking and Rental Manager Plugin to the latest available version (at least 2.7.8).


OpenCVE Recommended Actions

  • Update the Booking and Rental Manager plugin to version 2.7.8 or later.
  • If an upgrade is not possible, disable or remove the plugin to stop exposure.
  • Configure a Content Security Policy that blocks inline scripts or restricts script origins until the plugin is patched.

Generated by OpenCVE AI on September 3, 2026 at 20:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 03 Sep 2026 17:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Magepeople inc. Booking and Rental Manager allows Stored XSS. This issue affects Booking and Rental Manager: from n/a through 2.7.7.
Title WordPress Booking and Rental Manager plugin <= 2.7.7 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-09-03T17:33:24.213Z

Reserved: 2026-09-03T16:41:28.560Z

Link: CVE-2026-85303

cve-icon Vulnrichment

Updated: 2026-09-03T17:33:21.543Z

cve-icon NVD

Status : Deferred

Published: 2026-09-03T17:17:30.457

Modified: 2026-09-03T18:17:34.423

Link: CVE-2026-85303

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T20:30:10Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')