CyberRota Analysis
AI-GeneratedThe Booking System Trafft plugin for WordPress is vulnerable to Stored Cross-Site Scripting due to inadequate capability checks in the `set_options` AJAX action, allowing authenticated users to manipulate the `bookingWebsiteUrl` setting. This flaw enables attackers with Subscriber-level access or higher to inject malicious JavaScript into the front-end of the site, potentially compromising the security of all visitors, including administrators. WordPress site administrators using this plugin should prioritize patching or updating to mitigate the risk of exploitation.
Original NVD Description
The Booking System Trafft plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `bookingWebsiteUrl` setting in all versions up to, and including, 1.0.17 due to a missing capability check on the `set_options` AJAX action when the plugin is operating in agency mode. The `trafftSetOptions()` handler verifies a nonce that is exposed to any authenticated user (it is printed inline on every admin page, including profile.php) but performs no capability check before calling `update_option('trafft_option', ['bookingWebsiteUrl' => ...])`. This setting is then used by `trafftAdminAssets()` to enqueue `<bookingWebsiteUrl>/embed.js` as a script on every front-end page that renders the booking shortcode. This makes it possible for authenticated attackers, with Subscriber-level access and above, to point the embed-script URL at an attacker-controlled origin and execute arbitrary JavaScript in the browser of every site visitor (including admins).