---
id: CVE-2023-54358
title: >-
  WordPress adivaha Travel Plugin 2.3 contains a reflected cross-site scripting
  vulnerability that allows unauthenticated attackers to inject malicious
  scripts by manipulating the isMobile parameter
summary: >-
  WordPress adivaha Travel Plugin 2.3 contains a reflected cross-site scripting
  vulnerability that allows unauthenticated attackers to inject malicious
  scripts by manipulating the isMobile parameter. Attackers can craft malicious
  URLs cont…
severity: medium
cvss: 6.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
published: '2026-04-09'
updated: '2026-09-26'
sourceUpdated: '2026-09-26T23:10:00.127'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2023-54358'
references:
  - url: 'https://wordpress.org/plugins/adiaha-hotel/'
    label: disclosure@vulncheck.com
  - url: 'https://www.adivaha.com/'
    label: disclosure@vulncheck.com
  - url: 'https://www.exploit-db.com/exploits/51663'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/wordpress-adivaha-travel-plugin-reflected-xss-via-ismobile
    label: disclosure@vulncheck.com
tags:
  - nvd
epss: 0.00263
epssPercentile: 0.16257
ingestedAt: '2026-09-26T23:39:28.804Z'
---

## Overview

WordPress adivaha Travel Plugin 2.3 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the isMobile parameter. Attackers can craft malicious URLs containing JavaScript payloads in the isMobile GET parameter at the /mobile-app/v3/ endpoint to execute arbitrary code in victims' browsers and steal session tokens or credentials.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
