PT-2026-65782 · Ameliabooking · Booking System Trafft
CVSS v3.1
6.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N |
The Booking System Trafft plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the
bookingWebsiteUrl setting in all versions up to, and including, 1.0.17 due to a missing capability check on the set options AJAX action when the plugin is operating in agency mode. The trafftSetOptions() handler verifies a nonce that is exposed to any authenticated user (it is printed inline on every admin page, including profile.php) but performs no capability check before calling update option('trafft option', ['bookingWebsiteUrl' => ...]). This setting is then used by trafftAdminAssets() to enqueue <bookingWebsiteUrl>/embed.js as a script on every front-end page that renders the booking shortcode. This makes it possible for authenticated attackers, with Subscriber-level access and above, to point the embed-script URL at an attacker-controlled origin and execute arbitrary JavaScript in the browser of every site visitor (including admins).Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Booking System Trafft