CVE-2025-49904: WordPress Booking and Rental Manager plugin <= 2.5.3 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in magepeopleteam Booking and Rental Manager booking-and-rental-manager-for-woocommerce allows Reflected XSS.This issue affects Booking and Rental Manager: from n/a through <= 2.5.3.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-49904?
CVE-2025-49904 is classified as a reflected Cross-site Scripting (XSS) vulnerability.
How do I fix CVE-2025-49904?
To fix CVE-2025-49904, upgrade the Booking and Rental Manager plugin to version 2.5.4 or later.
Which software is affected by CVE-2025-49904?
CVE-2025-49904 affects the Booking and Rental Manager plugin from versions n/a through 2.5.3.
What are the implications of CVE-2025-49904?
CVE-2025-49904 allows attackers to execute JavaScript code in the context of the affected user's session.
How can I detect CVE-2025-49904 on my site?
You can detect CVE-2025-49904 by scanning your WordPress site for outdated versions of the Booking and Rental Manager plugin.