Cross-site Scripting Vulnerability in eZee Technosys Online Hotel Booking Engine
CVE-2025-58661

5.9MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
22 September 2025

What is CVE-2025-58661?

The eZee Online Hotel Booking Engine contains a Cross-site Scripting vulnerability that allows an attacker to inject malicious scripts into web pages. This issue can lead to stored XSS, where the injected scripts are executed in the browser of users who access affected pages. The vulnerability affects all versions leading up to and including 1.0.0, highlighting the necessity for users to implement security measures and update their software to safeguard against potential attacks.

Affected Version(s)

eZee Online Hotel Booking Engine <= 1.0.0

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Vinit Lakra (Patchstack Alliance)
.