VYPR
Unrated severityNVD Advisory· Published Jul 29, 2026· Updated Jul 29, 2026No known patch

Booking System Trafft <= 1.0.17 - Authenticated (Subscriber+) Stored Cross-Site Scripting

CVE-2026-8791

Description

The Booking System Trafft plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the bookingWebsiteUrl setting in all versions up to, and including, 1.0.17 due to a missing capability check on the set_options AJAX action when the plugin is operating in agency mode. The trafftSetOptions() handler verifies a nonce that is exposed to any authenticated user (it is printed inline on every admin page, including profile.php) but performs no capability check before calling update_option('trafft_option', ['bookingWebsiteUrl' => ...]). This setting is then used by trafftAdminAssets() to enqueue /embed.js as a script on every front-end page that renders the booking shortcode. This makes it possible for authenticated attackers, with Subscriber-level access and above, to point the embed-script URL at an attacker-controlled origin and execute arbitrary JavaScript in the browser of every site visitor (including admins).

Affected products

1

Patches

Vulnerability mechanics

References

11

News mentions

0

No linked articles in our index yet.