CVE-2026-39541: WordPress Hydra Booking plugin <= 1.1.38 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themefic Hydra Booking hydra-booking allows Stored XSS.This issue affects Hydra Booking: from n/a through <= 1.1.38.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-39541?
The severity of CVE-2026-39541 is rated as medium with a CVSS score of 5.9.
How do I fix CVE-2026-39541?
To fix CVE-2026-39541, update the WordPress Hydra Booking plugin to version 1.1.39 or later.
What impact does CVE-2026-39541 have on users?
CVE-2026-39541 allows attackers to exploit stored Cross Site Scripting (XSS) vulnerabilities, potentially leading to malicious script execution in users' browsers.
Which versions of the Hydra Booking plugin are affected by CVE-2026-39541?
CVE-2026-39541 affects all versions of the Hydra Booking plugin from its initial release through version 1.1.38.
Is CVE-2026-39541 considered a serious threat?
While CVE-2026-39541 has a medium severity, it poses a significant risk due to its potential for exploiting user data through XSS attacks.