Booking System Trafft <= 1.0.17 - Authenticated (Subscriber+) Stored Cross-Site Scripting
No known patch is available for this vulnerability.
The affected plugin has not been updated on WordPress.org since before this CVE was disclosed; the latest installable version is still vulnerable. If you have the affected software installed, you should uninstall or replace it rather than wait for an update.
Description
The Booking System Trafft plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the bookingWebsiteUrl setting in all versions up to, and including, 1.0.17 due to a missing capability check on the set_options AJAX action when the plugin is operating in agency mode. The trafftSetOptions() handler verifies a nonce that is exposed to any authenticated user (it is printed inline on every admin page, including profile.php) but performs no capability check before calling update_option('trafft_option', ['bookingWebsiteUrl' => ...]). This setting is then used by trafftAdminAssets() to enqueue /embed.js as a script on every front-end page that renders the booking shortcode. This makes it possible for authenticated attackers, with Subscriber-level access and above, to point the embed-script URL at an attacker-controlled origin and execute arbitrary JavaScript in the browser of every site visitor (including admins).
Affected products
1- Range: <=1.0.17
Patches
Vulnerability mechanics
References
11- plugins.trac.wordpress.org/browser/booking-system-trafft/tags/1.0.17/trafft.phpmitre
- plugins.trac.wordpress.org/browser/booking-system-trafft/tags/1.0.17/trafft.phpmitre
- plugins.trac.wordpress.org/browser/booking-system-trafft/tags/1.0.17/trafft.phpmitre
- plugins.trac.wordpress.org/browser/booking-system-trafft/tags/1.0.17/trafft.phpmitre
- plugins.trac.wordpress.org/browser/booking-system-trafft/tags/1.0.17/trafft.phpmitre
- plugins.trac.wordpress.org/browser/booking-system-trafft/trunk/trafft.phpmitre
- plugins.trac.wordpress.org/browser/booking-system-trafft/trunk/trafft.phpmitre
- plugins.trac.wordpress.org/browser/booking-system-trafft/trunk/trafft.phpmitre
- plugins.trac.wordpress.org/browser/booking-system-trafft/trunk/trafft.phpmitre
- plugins.trac.wordpress.org/browser/booking-system-trafft/trunk/trafft.phpmitre
- www.wordfence.com/threat-intel/vulnerabilities/id/e93060cf-2df3-4d45-a1f2-304f443d58bcmitre
News mentions
0No linked articles in our index yet.