CVE-2025-64275: WordPress Booking Manager plugin <= 2.1.17 - Cross Site Scripting (XSS) vulnerability
Published Nov 13, 2025
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdevelop Booking Manager booking-manager allows Stored XSS.This issue affects Booking Manager: from n/a through <= 2.1.17.
Affected Software
2 affected components
wpdevelop Booking Manager<=2.1.17
WordPress Booking Manager<=2.1.17
Event History
Nov 13, 2025
CVE Published
via MITRE·09:24 AM
Data Sourced
via MITRE·09:24 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-64275?
CVE-2025-64275 has a high severity rating due to the potential for stored cross-site scripting attacks.
2
How do I fix CVE-2025-64275?
To fix CVE-2025-64275, update the Booking Manager plugin to version 2.1.18 or later.
3
What types of attacks does CVE-2025-64275 allow?
CVE-2025-64275 allows attackers to execute stored cross-site scripting (XSS) attacks, potentially compromising user data.
4
Which versions of Booking Manager are affected by CVE-2025-64275?
CVE-2025-64275 affects all versions of Booking Manager up to and including version 2.1.17.
5
Is CVE-2025-64275 a common vulnerability?
Yes, cross-site scripting vulnerabilities like CVE-2025-64275 are relatively common in web applications.