PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-103305 Prenotazioni CVE debrief

The Prenotazioni WordPress plugin through 1.7.5 is vulnerable to Stored Cross-Site Scripting attacks. This vulnerability allows unauthenticated users to perform Stored Cross-Site Scripting attacks against administrators and site visitors due to lack of authorisation and CSRF checks when saving settings, and insufficient escaping of some settings when outputting them. Defenders should prioritize verifying exposure and potential updates. The vulnerability has a significant impact on site integrity and user trust if exploited.

Vendor
Prenotazioni
Product
Prenotazioni WordPress plugin
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-11
Original CVE updated
2026-10-11
Advisory published
2026-10-11
Advisory updated
2026-10-11

Who should care

WordPress administrators and defenders responsible for maintaining WordPress installations with the Prenotazioni plugin should assess exposure and prioritize verification and potential updates.

Why it matters

CVE-2026-103305 is a Stored Cross-Site Scripting vulnerability in the Prenotazioni WordPress plugin. Defenders should prioritize verifying exposure and potential updates due to the risk of Stored Cross-Site Scripting attacks against administrators and site visitors.

  • Potential Stored Cross-Site Scripting attacks against administrators and site visitors
  • Need to verify the presence of the vulnerable plugin version in WordPress installations
  • Potential impact on site integrity and user trust if exploited

Technical summary

The Prenotazioni WordPress plugin through 1.7.5 does not have authorisation and CSRF checks when saving its settings, and does not escape some of them when outputting them. This allows unauthenticated users to perform Stored Cross-Site Scripting attacks against administrators and site visitors. The vulnerability is caused by insufficient escaping of some settings when outputting them, and lack of authorisation and CSRF checks when saving settings. Defenders should prioritize verifying exposure and potential updates due to the risk of Stored Cross-Site Scripting attacks.

Defensive priority

Defenders should prioritize verifying the presence of this vulnerability in their WordPress installations and updating the Prenotazioni plugin to a fixed version if available.

Recommended defensive actions

  • Verify the presence of the Prenotazioni plugin in your WordPress installation
  • Check if the plugin version is 1.7.5 or earlier
  • Update the plugin to a fixed version if available
  • Monitor for potential Stored Cross-Site Scripting attacks
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance

Evidence notes

The CVE record and NVD entry provide limited information about the vulnerability. The primary source is a WordPress plugin vulnerability report from WPScan. Defenders should verify the presence of the Prenotazioni plugin in their WordPress installations and check if the plugin version is 1.7.5 or earlier. The vulnerability allows for Stored Cross-Site Scripting attacks against administrators and site visitors. Evidence is limited, and further verification is required to confirm affected scope and severity.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-103305 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-103305

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-103305 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-103305

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.