SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-8791

MEDIUM · CVSS 6.4 EPSS 0.23%

Source: NVD + CISA KEV + EPSS · Published 2026-07-29 · Last synced 2026-08-28

CyberRota Analysis

AI-Generated

The Booking System Trafft plugin for WordPress is vulnerable to Stored Cross-Site Scripting due to inadequate capability checks in the `set_options` AJAX action, allowing authenticated users to manipulate the `bookingWebsiteUrl` setting. This flaw enables attackers with Subscriber-level access or higher to inject malicious JavaScript into the front-end of the site, potentially compromising the security of all visitors, including administrators. WordPress site administrators using this plugin should prioritize patching or updating to mitigate the risk of exploitation.

CVE
CVE-2026-8791
Severity
MEDIUM
CVSS
6.4
EPSS
0.23%
WordPress Java

Original NVD Description

The Booking System Trafft plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `bookingWebsiteUrl` setting in all versions up to, and including, 1.0.17 due to a missing capability check on the `set_options` AJAX action when the plugin is operating in agency mode. The `trafftSetOptions()` handler verifies a nonce that is exposed to any authenticated user (it is printed inline on every admin page, including profile.php) but performs no capability check before calling `update_option('trafft_option', ['bookingWebsiteUrl' => ...])`. This setting is then used by `trafftAdminAssets()` to enqueue `<bookingWebsiteUrl>/embed.js` as a script on every front-end page that renders the booking shortcode. This makes it possible for authenticated attackers, with Subscriber-level access and above, to point the embed-script URL at an attacker-controlled origin and execute arbitrary JavaScript in the browser of every site visitor (including admins).