CVE-2025-58661
Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in eZee Technosys eZee Online Hotel Booking Engine online-booking-engine allows Stored XSS.This issue affects eZee Online Hotel Booking Engine: from n/a through <= 1.0.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Stored XSS in eZee Online Hotel Booking Engine ≤1.0.0 allows attackers to inject malicious scripts executed when guests visit the site.
Vulnerability
Overview CVE-2025-58661 is a stored cross-site scripting (XSS) vulnerability in the eZee Online Hotel Booking Engine plugin for WordPress, affecting all versions up to and including 1.0.0. The issue arises from improper neutralization of user input during web page generation, allowing attackers to inject arbitrary HTML and JavaScript code that is stored on the server and later executed in the browsers of site visitors [1].
Exploitation
Requirements Exploitation requires an authenticated user with certain privileges; the specific role is not disclosed but the vulnerability is triggered via the plugin's admin interface. Successful execution depends on a privileged user performing an action such as clicking a malicious link or submitting crafted input. Once injected, the malicious payload is stored and delivered to all subsequent visitors without further interaction [1].
Impact
An attacker can inject scripts that perform arbitrary actions in the context of the victim's browser, including redirecting users to malicious sites, displaying unwanted advertisements, or stealing sensitive information. This can lead to defacement, phishing attacks, or further compromise of the affected site and its users [1].
Mitigation
As of the publication date, no patch is available for versions ≤1.0.0. The vendor is urged to release an update. In the meantime, users should consider disabling the plugin or applying a web application firewall rule to mitigate XSS attacks. Given the potential for mass exploitation, immediate action is recommended [1].
AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: <=1.0.0
- Range: <=1.0.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.