Executive brief
Magepeople's Booking and Rental Manager is a WordPress plugin that handles booking and rental reservations for WooCommerce stores. The plugin contains a stored cross-site scripting (XSS) vulnerability that allows attackers with contributor or higher privileges to inject malicious scripts into the website. When visitors interact with the compromised pages or data, the injected scripts can execute in their browsers, potentially stealing session data, credentials, or performing actions on behalf of legitimate users.
Technical details
This is a stored XSS vulnerability in the Booking and Rental Manager plugin for WordPress, affecting versions up to 2.7.7. The vulnerability exists due to improper neutralization of user input during web page generation, allowing authenticated attackers with contributor-level privileges or higher to inject malicious JavaScript code that persists in the database. The attack requires user interaction (e.g., a privileged user clicking a link or visiting a crafted page), but once injected, the payload executes for all site visitors viewing the affected content. The vulnerability was patched in version 2.7.8, and updates should be applied immediately to affected WordPress installations.
Affected products
- Magepeople inc. Booking and Rental Manager through 2.7.7
Timeline
- 2026-09-03: disclosed
- 2026-09-03: patched: Version 2.7.8 or later