CVE-2026-8791
No known patch is available for this vulnerability.
The affected plugin has not been updated on WordPress.org since before this CVE was disclosed; the latest installable version is still vulnerable. If you have the affected software installed, you should uninstall or replace it rather than wait for an update.
Description
The Booking System Trafft plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the bookingWebsiteUrl setting in all versions up to, and including, 1.0.17 due to a missing capability check on the set_options AJAX action when the plugin is operating in agency mode. The trafftSetOptions() handler verifies a nonce that is exposed to any authenticated user (it is printed inline on every admin page, including profile.php) but performs no capability check before calling update_option('trafft_option', ['bookingWebsiteUrl' => ...]). This setting is then used by trafftAdminAssets() to enqueue /embed.js as a script on every front-end page that renders the booking shortcode. This makes it possible for authenticated attackers, with Subscriber-level access and above, to point the embed-script URL at an attacker-controlled origin and execute arbitrary JavaScript in the browser of every site visitor (including admins).
Affected products
1- Range: <=1.0.17
Patches
Vulnerability mechanics
References
11- plugins.trac.wordpress.org/browser/booking-system-trafft/tags/1.0.17/trafft.phpnvd
- plugins.trac.wordpress.org/browser/booking-system-trafft/tags/1.0.17/trafft.phpnvd
- plugins.trac.wordpress.org/browser/booking-system-trafft/tags/1.0.17/trafft.phpnvd
- plugins.trac.wordpress.org/browser/booking-system-trafft/tags/1.0.17/trafft.phpnvd
- plugins.trac.wordpress.org/browser/booking-system-trafft/tags/1.0.17/trafft.phpnvd
- plugins.trac.wordpress.org/browser/booking-system-trafft/trunk/trafft.phpnvd
- plugins.trac.wordpress.org/browser/booking-system-trafft/trunk/trafft.phpnvd
- plugins.trac.wordpress.org/browser/booking-system-trafft/trunk/trafft.phpnvd
- plugins.trac.wordpress.org/browser/booking-system-trafft/trunk/trafft.phpnvd
- plugins.trac.wordpress.org/browser/booking-system-trafft/trunk/trafft.phpnvd
- www.wordfence.com/threat-intel/vulnerabilities/id/e93060cf-2df3-4d45-a1f2-304f443d58bcnvd
News mentions
2- Wordfence Intelligence Weekly WordPress Vulnerability Report (August 3, 2026 to August 9, 2026)Wordfence Blog · Aug 14, 2026
- Wordfence Intelligence Weekly WordPress Vulnerability Report (July 27, 2026 to August 2, 2026)Wordfence Blog · Aug 8, 2026