CVE-2026-1645 | prasunsen Hostel Plugin up to 1.1.8 on WordPress custom_currency/locale_url cross site scripting

SecurityVulns

A vulnerability was found in prasunsen Hostel Plugin up to 1.1.8 on WordPress. It has been classified as problematic. The impacted element is an unknown function. The manipulation of the argument custom_currency/locale_url leads to cross site scripting.

This vulnerability is documented as CVE-2026-1645. The attack can be initiated remotely. There is not any exploit available.VulDB Recent EntriesRead More