What is CVE-2026-8791?
The Booking System Trafft plugin for WordPress contains a Stored Cross-Site Scripting vulnerability via the `bookingWebsiteUrl` setting due to a missing capability check. Authenticated attackers can inject malicious scripts, affecting versions up to 1.0.17. Immediate update is recommended.
Azərbaycanca: WordPress üçün Booking System Trafft plaginində saxlanılan XSS zəifliyi aşkarlanıb. Bu, `bookingWebsiteUrl` parametrinin düzgün yoxlanılmaması səbəbindən autentifikasiya olunmuş hücumçulara zərərli skript yerləşdirməyə imkan verir. Plaginin 1.0.17 və əvvəlki versiyaları təsir altındadır; dərhal yeniləmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which versions of the Trafft plugin are affected by CVE-2026-8791?
The vulnerability affects Trafft plugin versions 1.0.17 and earlier.
Is authentication required to exploit this Stored XSS vulnerability?
Yes, an attacker must be authenticated to exploit this vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.