VulnerabilityModified
CVE-2020-15536
Persistent XSS can occur via any of the registration fields.
MEDIUM 6.1EPSS 1.17%
Does this matter?
Lower severity and a low EPSS score (1.17%). Track it; it rarely justifies an emergency change on its own.
Description
An issue was discovered in the bestsoftinc Hotel Booking System Pro plugin through 1.1 for WordPress. Persistent XSS can occur via any of the registration fields.
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 1.17% probability · 66th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- online hotel booking system project/online hotel booking system
- Source
- cve@mitre.org
References
- https://packetstormsecurity.com/files/157116/WordPress-Hotel-Booking-System-Pro-1.1-Cross-Site-Scripting.htmlExploit, Third Party Advisory, VDB Entry
- https://wpvulndb.com/vulnerabilities/10171Third Party Advisory
- https://packetstormsecurity.com/files/157116/WordPress-Hotel-Booking-System-Pro-1.1-Cross-Site-Scripting.htmlExploit, Third Party Advisory, VDB Entry
- https://wpvulndb.com/vulnerabilities/10171Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.