PatchSiren cyber security CVE debrief
CVE-2026-103305 Prenotazioni CVE debrief
The Prenotazioni WordPress plugin through 1.7.5 is vulnerable to Stored Cross-Site Scripting attacks. This vulnerability allows unauthenticated users to perform Stored Cross-Site Scripting attacks against administrators and site visitors due to lack of authorisation and CSRF checks when saving settings, and insufficient escaping of some settings when outputting them. Defenders should prioritize verifying exposure and potential updates. The vulnerability has a significant impact on site integrity and user trust if exploited.
- Vendor
- Prenotazioni
- Product
- Prenotazioni WordPress plugin
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-11
- Original CVE updated
- 2026-10-11
- Advisory published
- 2026-10-11
- Advisory updated
- 2026-10-11
Who should care
WordPress administrators and defenders responsible for maintaining WordPress installations with the Prenotazioni plugin should assess exposure and prioritize verification and potential updates.
Why it matters
CVE-2026-103305 is a Stored Cross-Site Scripting vulnerability in the Prenotazioni WordPress plugin. Defenders should prioritize verifying exposure and potential updates due to the risk of Stored Cross-Site Scripting attacks against administrators and site visitors.
- Potential Stored Cross-Site Scripting attacks against administrators and site visitors
- Need to verify the presence of the vulnerable plugin version in WordPress installations
- Potential impact on site integrity and user trust if exploited
Technical summary
The Prenotazioni WordPress plugin through 1.7.5 does not have authorisation and CSRF checks when saving its settings, and does not escape some of them when outputting them. This allows unauthenticated users to perform Stored Cross-Site Scripting attacks against administrators and site visitors. The vulnerability is caused by insufficient escaping of some settings when outputting them, and lack of authorisation and CSRF checks when saving settings. Defenders should prioritize verifying exposure and potential updates due to the risk of Stored Cross-Site Scripting attacks.
Defensive priority
Defenders should prioritize verifying the presence of this vulnerability in their WordPress installations and updating the Prenotazioni plugin to a fixed version if available.
Recommended defensive actions
- Verify the presence of the Prenotazioni plugin in your WordPress installation
- Check if the plugin version is 1.7.5 or earlier
- Update the plugin to a fixed version if available
- Monitor for potential Stored Cross-Site Scripting attacks
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
Evidence notes
The CVE record and NVD entry provide limited information about the vulnerability. The primary source is a WordPress plugin vulnerability report from WPScan. Defenders should verify the presence of the Prenotazioni plugin in their WordPress installations and check if the plugin version is 1.7.5 or earlier. The vulnerability allows for Stored Cross-Site Scripting attacks against administrators and site visitors. Evidence is limited, and further verification is required to confirm affected scope and severity.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-103305 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-103305
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-103305 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-103305
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://wpscan.com/vulnerability/9fde6498-7d23-4419-9416-d5f50ca97c4a/
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.