PatchSiren

Prenotazioni CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Review Prenotazioni CVE published 2026-10-11

CVE-2026-103305

The Prenotazioni WordPress plugin through 1.7.5 is vulnerable to Stored Cross-Site Scripting attacks. This vulnerability allows unauthenticated users to perform Stored Cross-Site Scripting attacks against administrators and site visitors due to lack of authorisation and CSRF checks when saving settings, and insufficient escaping of some settings when outputting them. Defenders should prioritize verifying [truncated]