Unrated severityNVD Advisory· Published Jun 15, 2022· Updated Apr 28, 2026
WordPress Travel Management plugin <= 2.0 - Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities
CVE-2022-27859
Description
Multiple Authenticated (contributor or higher user role) Stored Cross-Site Scripting (XSS) vulnerabilities in Nicdark d.o.o. Travel Management plugin <= 2.0 at WordPress.
Affected products
1- Range: <= 2.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- patchstack.com/database/vulnerability/nd-travel/wordpress-travel-management-plugin-2-0-multiple-authenticated-stored-cross-site-scripting-xss-vulnerabilitiesmitrex_refsource_CONFIRM
- wordpress.org/plugins/nd-travel/mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.