← WordPress Vulnerabilities
WordPress security by component

Hostel

Hostel is a WordPress component with 13 published CVE records in this archive. The latest tracked vulnerability was published Jul 10, 2026; the highest CVE/CNA score is 7.6.

Plugin slug: hostel

CVE-2026-3907: Hostel: Cross-site scripting

Hostel is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 1.1.7.

PublishedJul 10, 2026
Known safe version> 1.1.7
Safe version
Jul 10, 2026 CVE-2026-3907
Hostel: Cross-site scripting
Hostel is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 1.1.7.
> 1.1.7
CVE6.4
NVDPending
Apr 18, 2026 CVE-2026-1838
Hostel: Cross-site scripting
Hostel is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 1.1.6.
> 1.1.6
CVE6.1
NVDPending
Dec 24, 2025 CVE-2023-32120
Hostel: Cross-site scripting
Hostel is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.9
NVDPending
Dec 18, 2025 CVE-2025-66119
Hostel: Cross-site scripting
Hostel is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.1
NVDPending
Jul 10, 2025 CVE-2025-6236
Hostel: Cross-site scripting
Hostel is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.8
NVDPending
Jul 10, 2025 CVE-2025-6234
Hostel: Cross-site scripting
Hostel is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVDPending
Apr 16, 2025 CVE-2025-39566
Hostel: SQL injection
Hostel is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE7.6
NVDPending
Apr 01, 2025 CVE-2025-30848
Hostel: Cross-site scripting
Hostel is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.1
NVDPending
Mar 28, 2025 CVE-2025-31102
Hostel: Cross-site scripting
Hostel is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.1
NVDPending
Jul 13, 2024 CVE-2024-3753
Hostel: Cross-site scripting
Hostel is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.9
NVDPending
May 14, 2024 CVE-2024-4314
Hostel: Cross-site request forgery
Hostel is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVDPending
Jun 05, 2023 CVE-2023-0545
Hostel: Cross-site scripting
Hostel is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.8
NVD4.8
May 27, 2019 CVE-2019-12345
Hostel: Cross-site scripting
Hostel is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1