eZee Online Hotel Booking Engine Security & Risk Analysis

wordpress.org/plugins/online-booking-engine

eZee Reservation plugin is solutions for hotel, resorts, B&B, hotel chains, to get commission free online bookings from their own hotel website.

100 active installs v1.0.0 PHP + WP 3.0.1+ Updated Mar 12, 2020
accommodationsavailabilitybed-and-breakfastreservationreserve-room
63
C · Use Caution
CVEs total1
Unpatched1
Last CVESep 22, 2025
Download
Safety Verdict

Is eZee Online Hotel Booking Engine Safe to Use in 2026?

Use With Caution

Score 63/100

eZee Online Hotel Booking Engine has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.

1 known CVE 1 unpatched Last CVE: Sep 22, 2025Updated 6yr ago
Risk Assessment

The "online-booking-engine" plugin version 1.0.0 presents a mixed security posture. While the static analysis shows a minimal attack surface with no unprotected entry points, zero dangerous functions, and all SQL queries using prepared statements, several significant concerns are present. Notably, 100% of the identified output operations are not properly escaped, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities. The absence of nonce checks and capability checks across its entry points further exacerbates this risk, as these are fundamental security mechanisms for WordPress plugins.

The vulnerability history reveals a concerning pattern. There is one known medium severity CVE related to Cross-Site Scripting, which is currently unpatched. The fact that the last vulnerability was dated in the future (2025-09-22) suggests a potential reporting anomaly or a proactive security disclosure, but the existence of an unpatched medium vulnerability in a past version is a significant red flag. The combination of unescaped output and a known XSS vulnerability points to a high likelihood of successful XSS attacks, especially given the lack of robust input validation or authorization checks on its single shortcode entry point.

In conclusion, despite some positive static analysis findings like prepared SQL statements and a small attack surface, the plugin's security is significantly undermined by its failure to escape output and its history of unpatched vulnerabilities, particularly XSS. These weaknesses, coupled with the lack of nonce and capability checks, create a considerable risk for sites utilizing this plugin.

Key Concerns

  • Unpatched CVE exists
  • Output is not properly escaped
  • No nonce checks found
  • No capability checks found
Vulnerabilities
1

eZee Online Hotel Booking Engine Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-58661medium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

eZee Online Hotel Booking Engine <= 1.0.0 - Authenticated (Administrator+) Stored Cross-Site Scripting

Sep 22, 2025Unpatched
Code Analysis
Analyzed Mar 16, 2026

eZee Online Hotel Booking Engine Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped2 total outputs
Attack Surface

eZee Online Hotel Booking Engine Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[ezee_booking_engine_code] wp_ezee_reservation.php:105
WordPress Hooks 4
actionadmin_menuwp_ezee_reservation.php:18
actioninitwp_ezee_reservation.php:31
actionwp_footerwp_ezee_reservation.php:32
actionwp_enqueue_scriptswp_ezee_reservation.php:50
Maintenance & Trust

eZee Online Hotel Booking Engine Maintenance & Trust

Maintenance Signals

WordPress version tested5.4.19
Last updatedMar 12, 2020
PHP min version
Downloads18K

Community Trust

Rating46/100
Number of ratings6
Active installs100
Developer Profile

eZee Online Hotel Booking Engine Developer Profile

eZee Technosys

1 plugin · 100 total installs

68
trust score
Avg Security Score
63/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect eZee Online Hotel Booking Engine

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/online-booking-engine/css/ezee.css/wp-content/plugins/online-booking-engine/js/ezee-res.js
Version Parameters
online-booking-engine-script?ver=1.0

HTML / DOM Fingerprints

CSS Classes
ezeesettingfrmcodeinfoeditframe
Data Attributes
name="editframe"id="editframe"class="editframe"
JS Globals
window.ezeebe_add_front_script
Shortcode Output
<iframe src="https://live.ipms247.com/booking/book-rooms-name="editframe"class="editframe"id="editframe"
FAQ

Frequently Asked Questions about eZee Online Hotel Booking Engine