VYPR
Medium severity5.9NVD Advisory· Published Sep 22, 2025· Updated Apr 23, 2026

CVE-2025-58661

CVE-2025-58661

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in eZee Technosys eZee Online Hotel Booking Engine online-booking-engine allows Stored XSS.This issue affects eZee Online Hotel Booking Engine: from n/a through <= 1.0.0.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Stored XSS in eZee Online Hotel Booking Engine ≤1.0.0 allows attackers to inject malicious scripts executed when guests visit the site.

Vulnerability

Overview CVE-2025-58661 is a stored cross-site scripting (XSS) vulnerability in the eZee Online Hotel Booking Engine plugin for WordPress, affecting all versions up to and including 1.0.0. The issue arises from improper neutralization of user input during web page generation, allowing attackers to inject arbitrary HTML and JavaScript code that is stored on the server and later executed in the browsers of site visitors [1].

Exploitation

Requirements Exploitation requires an authenticated user with certain privileges; the specific role is not disclosed but the vulnerability is triggered via the plugin's admin interface. Successful execution depends on a privileged user performing an action such as clicking a malicious link or submitting crafted input. Once injected, the malicious payload is stored and delivered to all subsequent visitors without further interaction [1].

Impact

An attacker can inject scripts that perform arbitrary actions in the context of the victim's browser, including redirecting users to malicious sites, displaying unwanted advertisements, or stealing sensitive information. This can lead to defacement, phishing attacks, or further compromise of the affected site and its users [1].

Mitigation

As of the publication date, no patch is available for versions ≤1.0.0. The vendor is urged to release an update. In the meantime, users should consider disabling the plugin or applying a web application firewall rule to mitigate XSS attacks. Given the potential for mass exploitation, immediate action is recommended [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.