A vulnerability identified as problematic has been detected in ameliabooking Booking System Trafft Plugin up to 1.0.17 on WordPress. Affected is the function trafftSetOptions of the file profile.php of the component Ajax Action. Performing a manipulation of the argument bookingWebsiteUrl results in cross site scripting.

This vulnerability is identified as CVE-2026-8791. The attack can be initiated remotely. There is not any exploit available.