WordPress adivaha Travel Plugin 2.3 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the isMobile parameter. Attackers can craft malicious URLs containing JavaScript payloads in the isMobile GET parameter at the /mobile-app/v3/ endpoint to execute arbitrary code in victims' browsers and steal session tokens or credentials.
Metrics
Affected Vendors & Products
References
History
Fri, 10 Apr 2026 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Adivaha
Adivaha wordpress Adivaha Travel Plugin Wordpress Wordpress wordpress |
|
| Vendors & Products |
Adivaha
Adivaha wordpress Adivaha Travel Plugin Wordpress Wordpress wordpress |
Thu, 09 Apr 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | WordPress adivaha Travel Plugin 2.3 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the isMobile parameter. Attackers can craft malicious URLs containing JavaScript payloads in the isMobile GET parameter at the /mobile-app/v3/ endpoint to execute arbitrary code in victims' browsers and steal session tokens or credentials. | |
| Title | WordPress adivaha Travel Plugin 2.3 Reflected XSS via isMobile | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-04-09T20:55:45.818Z
Reserved: 2026-04-09T20:41:29.868Z
Link: CVE-2023-54358
No data.
Status : Received
Published: 2026-04-09T21:16:04.960
Modified: 2026-04-09T21:16:04.960
Link: CVE-2023-54358
No data.