EIP-2026-113810
PRE-CVEWordPress Plugin Hotel Listing 3 - 'Multiple' Cross-Site Scripting (XSS)
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-113810. PoCs published by Vulnerability-Lab.
AI-analyzed exploit summary This is a detailed technical writeup describing a persistent XSS vulnerability in the WordPress Hotel Listing plugin v3.x. It includes affected input fields, exploitation steps, and a proof-of-concept payload.
Description
WordPress Plugin Hotel Listing 3 - 'Multiple' Cross-Site Scripting (XSS)
Exploits (1)
exploitdb
WRITEUP
by Vulnerability-Lab · textwebappsphp
https://www.exploit-db.com/exploits/50476
This is a detailed technical writeup describing a persistent XSS vulnerability in the WordPress Hotel Listing plugin v3.x. It includes affected input fields, exploitation steps, and a proof-of-concept payload.
Classification
Writeup 95%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target:
Hotel Listing WordPress Plugin v3.x
Auth required
Prerequisites:
Low-privileged user account on the WordPress site
MITRE ATT&CK
devstral-2 · analyzed Feb 18, 2026
Full analysis →
Details
Status
pre_cve
Tracked Since
Feb 18, 2026