Junglewise Threat Intelligence

CVE-2026-15464: ThimPress WP Hotel Booking Stored XSS in widget_search shortcode

CVE-2026-15464 · Severity: medium · CVSS 6.4 · Published 2026-07-24

Vendors: ThimPress.

Executive brief

The WP Hotel Booking plugin for WordPress, which provides reservation and management features for hospitality websites, contains a security flaw that allows users with contributor-level access to inject malicious scripts into pages. These scripts execute when other users visit the affected pages, potentially leading to unauthorized actions or data theft. The vulnerability is specifically exploitable in web browsers that support access keys, as the malicious code is hidden within certain page attributes.

Technical details

The WP Hotel Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on the 'widget_search' shortcode attribute. Authenticated attackers with contributor-level permissions or higher can exploit this by injecting arbitrary web scripts into a page. The payload is stored within a hidden attribute, making it primarily exploitable on browsers where access keys can be triggered to execute the script. The vulnerability exists in all versions up to and including 2.3.2; a patch was introduced in subsequent updates (changeset 3609563).

Affected products

  • ThimPress WP Hotel Booking up to, and including, 2.3.2

Timeline

  • 2026-07-24: disclosed
  • 2026-07-24: advisory

References