Stored Cross-Site Scripting Vulnerability in WP Hotel Booking Plugin for WordPress
CVE-2026-15464
6.4MEDIUM
What is CVE-2026-15464?
The WP Hotel Booking plugin for WordPress is exposed to a Stored Cross-Site Scripting vulnerability, allowing authenticated users with contributor-level access or higher to exploit the 'widget_search' Shortcode Attribute. Insufficient input sanitization and output escaping in all versions up to and including 2.3.2 facilitates the injection of arbitrary web scripts into web pages. This malicious code executes when users access affected pages, particularly in browsers that support access keys for exploit payloads stored in hidden attributes.
Affected Version(s)
WP Hotel Booking 0 <= 2.3.2