Kibokolabs Hostel vulnerabilities

5 known vulnerabilities affecting kibokolabs/hostel.

Total CVEs
5
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
MEDIUM5

Vulnerabilities

Page 1 of 1
CVE-2025-6234MEDIUMCVSS 6.1fixed in 1.1.5.82025-07-10
CVE-2025-6234 [MEDIUM] CWE-79 CVE-2025-6234: The Hostel WordPress plugin before 1.1.5.8 does not sanitise and escape a parameter before outputtin The Hostel WordPress plugin before 1.1.5.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
nvd
CVE-2025-6236MEDIUMCVSS 4.8fixed in 1.1.5.92025-07-10
CVE-2025-6236 [MEDIUM] CWE-79 CVE-2025-6236: The Hostel WordPress plugin before 1.1.5.9 does not sanitise and escape some of its settings, which The Hostel WordPress plugin before 1.1.5.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
nvd
CVE-2024-3753MEDIUMCVSS 5.9PoCfixed in 1.1.5.32024-07-13
CVE-2024-3753 [MEDIUM] CWE-79 CVE-2024-3753: The Hostel WordPress plugin before 1.1.5.3 does not sanitise and escape a parameter before outputtin The Hostel WordPress plugin before 1.1.5.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
nvd
CVE-2023-0545MEDIUMCVSS 4.8≤ 1.1.52023-06-05
CVE-2023-0545 [MEDIUM] CWE-79 CVE-2023-0545: The Hostel WordPress plugin before 1.1.5.2 does not sanitise and escape some of its settings, which The Hostel WordPress plugin before 1.1.5.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
nvd
CVE-2019-12345MEDIUMCVSS 6.1fixed in 1.1.42019-05-27
CVE-2019-12345 [MEDIUM] CWE-79 CVE-2019-12345: XSS exists in the Kiboko Hostel plugin before 1.1.4 for WordPress. XSS exists in the Kiboko Hostel plugin before 1.1.4 for WordPress.
nvd