Cross-site Scripting Vulnerability in ThimPress WP Hotel Booking Plugin
CVE-2025-63011
5.9MEDIUM
What is CVE-2025-63011?
The WP Hotel Booking plugin by ThimPress is affected by a cross-site scripting (XSS) vulnerability that arises from improper input neutralization during web page generation. This flaw allows attackers to exploit DOM-based XSS, potentially leading to unauthorized actions on behalf of users. The vulnerability impacts versions of the plugin up to and including 2.2.7, posing a significant security risk for websites utilizing this plugin.
Affected Version(s)
WP Hotel Booking <= n/a