Medium 4.8
2025-07-10< 1.1.5.9
Hostel <= 1.1.5.8 - Authenticated (Admin+) Stored Cross-Site Scripting
Minimum safe version
1.1.7
Update to 1.1.7 or later to address 13 fixable vulnerabilities
Hostel <= 1.1.5.8 - Authenticated (Admin+) Stored Cross-Site Scripting
Hostel <= 1.1.5.7 - Reflected Cross-Site Scripting
CVE-2026-1838
CVE-2025-66119
CVE-2025-39566
CVE-2025-30848
CVE-2025-31102
WordPress Hostel Plugin < 1.1.5.3 is vulnerable to Cross Site Scripting (XSS)
CVE-2024-4314
CVE-2023-0545
CVE-2023-32120
WordPress Hostel plugin <= 1.1.3 - Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability
CVE-2019-12345