Executive brief
The WP Hotel Booking plugin for WordPress, which manages room reservations and bookings, is vulnerable to a security flaw that allows attackers to run malicious scripts in a user's browser. This occurs when a user clicks a specially crafted link containing malicious data in the check-in or check-out date fields. If exploited, an attacker could potentially steal session information or perform unauthorized actions on behalf of the user.
Technical details
The WP Hotel Booking plugin for WordPress is vulnerable to Reflected Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on the 'check_in_date' and 'check_out_date' parameters. An unauthenticated remote attacker can exploit this by tricking a user into clicking a malicious link, which executes arbitrary JavaScript in the context of the user's browser session. The vulnerability exists in multiple components including Elementor widgets and search templates. A fix appears to be available in version 2.3.2, as indicated by the reference links to updated tags in the plugin repository.
Affected products
- thimpress WP Hotel Booking <= 2.3.1
Timeline
- 2026-07-10: disclosed
- 2026-07-10: advisory
References
- https://plugins.trac.wordpress.org/browser/wp-hotel-booking/tags/2.3.1/includes/class-wphb-helpers.php
- https://plugins.trac.wordpress.org/browser/wp-hotel-booking/tags/2.3.1/includes/elementor/widgets/archive-room/list-results-room.php
- https://plugins.trac.wordpress.org/browser/wp-hotel-booking/tags/2.3.1/includes/wphb-functions.php
- https://plugins.trac.wordpress.org/browser/wp-hotel-booking/tags/2.3.1/templates/search/loop.php
- https://plugins.trac.wordpress.org/browser/wp-hotel-booking/tags/2.3.1/templates/search/v2/loop-v2.php
- https://plugins.trac.wordpress.org/browser/wp-hotel-booking/tags/2.3.2/includes/elementor/widgets/archive-room/list-results-room.php
- https://plugins.trac.wordpress.org/browser/wp-hotel-booking/tags/2.3.2/templates/search/loop.php