
CVE-2026-1838 The Hostel plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'shortcode_id' parameter in all versions up to, and including, 1.1.6 due to insu… https://www.cve.org/CVERecord?id=CVE-2026-1838
Post summary
The Hostel WordPress plugin is disclosed as vulnerable to Reflected XSS via the 'shortcode_id' parameter in all versions up to 1.1.6. No PoC, exploit, or patch details are mentioned.

