Review
Prenotazioni
CVE published 2026-10-11
CVE-2026-103305
The Prenotazioni WordPress plugin through 1.7.5 is vulnerable to Stored Cross-Site Scripting attacks. This vulnerability allows unauthenticated users to perform Stored Cross-Site Scripting attacks against administrators and site visitors due to lack of authorisation and CSRF checks when saving settings, and insufficient escaping of some settings when outputting them. Defenders should prioritize verifying [truncated]