CVE-2023-54358

WordPress adivaha Travel Plugin 2.3 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the isMobile parameter. Attackers can craft malicious URLs containing JavaScript payloads in the isMobile GET parameter at the /mobile-app/v3/ endpoint to execute arbitrary code in victims' browsers and steal session tokens or credentials.
Configurations

No configuration.

History

09 Apr 2026, 21:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-09 21:16

Updated : 2026-04-15 15:00


NVD link : CVE-2023-54358

Mitre link : CVE-2023-54358

CVE.ORG link : CVE-2023-54358


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')