WordPress adivaha Travel Plugin 2.3 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the isMobile parameter. Attackers can craft malicious URLs containing JavaScript payloads in the isMobile GET parameter at the /mobile-app/v3/ endpoint to execute arbitrary code in victims' browsers and steal session tokens or credentials.
History

Fri, 10 Apr 2026 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 10 Apr 2026 09:00:00 +0000

Type Values Removed Values Added
First Time appeared Adivaha
Adivaha wordpress Adivaha Travel Plugin
Wordpress
Wordpress wordpress
Vendors & Products Adivaha
Adivaha wordpress Adivaha Travel Plugin
Wordpress
Wordpress wordpress

Thu, 09 Apr 2026 21:15:00 +0000

Type Values Removed Values Added
Description WordPress adivaha Travel Plugin 2.3 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the isMobile parameter. Attackers can craft malicious URLs containing JavaScript payloads in the isMobile GET parameter at the /mobile-app/v3/ endpoint to execute arbitrary code in victims' browsers and steal session tokens or credentials.
Title WordPress adivaha Travel Plugin 2.3 Reflected XSS via isMobile
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published: 2026-04-09T20:54:48.665Z

Updated: 2026-04-10T18:10:15.754Z

Reserved: 2026-04-09T20:41:29.868Z

Link: CVE-2023-54358

cve-icon Vulnrichment

Updated: 2026-04-10T18:10:12.222Z

cve-icon NVD

Status : Received

Published: 2026-04-09T21:16:04.960

Modified: 2026-04-09T21:16:04.960

Link: CVE-2023-54358

cve-icon Redhat

No data.