WordPress security by component
VikBooking Hotel Booking Engine & PMS
Plugin description
VikBooking Hotel Booking Engine & PMS is a WordPress component with 18 published CVE records in this archive. The latest tracked vulnerability was published Jul 24, 2026; the highest CVE/CNA score is 9.8.
Plugin slug:
vikbookingLatest vulnerability
CVE-2026-15401: VikBooking guest details permit unauthenticated stored XSS
VikBooking through 1.8.13 accepts unauthenticated booking submissions through the public saveorder task. Attacker-controlled vbf
| Safe version |
|
||
|---|---|---|---|
| Jul 24, 2026 |
CVE-2026-15401
VikBooking guest details permit unauthenticated stored XSS
VikBooking through 1.8.13 accepts unauthenticated booking submissions through the public saveorder task. Attacker-controlled vbf
|
1.8.14 |
CVE7.2
NVDPending
|
| Jul 24, 2026 |
CVE-2026-15346
VikBooking category filter permits reflected XSS
VikBooking through 1.8.13 reads the unauthenticated category_id request parameter in the public search view and reflects it into hidden category_id and categories input values without attribute escaping. A crafted link can therefore break out of the hidden input and execute script if a victim follows it and uses a browser or access-key interaction capable of activating the hidden control.
|
1.8.14 |
CVE6.1
NVDPending
|
| Jul 08, 2026 |
CVE-2026-6820
VikBooking Hotel Booking Engine & PMS: Cross-site scripting
VikBooking Hotel Booking Engine & PMS is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 1.8.8.
|
> 1.8.8 |
CVE7.2
NVDPending
|
| Jul 08, 2026 |
CVE-2026-6818
VikBooking Hotel Booking Engine & PMS: Cross-site scripting
VikBooking Hotel Booking Engine & PMS is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 1.8.8.
|
> 1.8.8 |
CVE7.2
NVDPending
|
| Jul 01, 2026 |
CVE-2026-57723
VikBooking Hotel Booking Engine & PMS: Filesystem traversal
VikBooking Hotel Booking Engine & PMS is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server. The published affected range is n/a through 1.8.12.
|
1.8.13 |
CVE7.4
NVDPending
|
| Jul 01, 2026 |
CVE-2026-12754
VikBooking Hotel Booking Engine & PMS: Cross-site scripting
VikBooking Hotel Booking Engine & PMS is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 1.8.12.
|
> 1.8.12 |
CVE6.1
NVDPending
|
| Jun 01, 2026 |
CVE-2026-42683
VikBooking Hotel Booking Engine & PMS: Cross-site scripting
VikBooking Hotel Booking Engine & PMS is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 1.8.8.
|
1.8.9 |
CVE7.1
NVDPending
|
| May 27, 2026 |
CVE-2026-42762
VikBooking Hotel Booking Engine & PMS: Cross-site scripting
VikBooking Hotel Booking Engine & PMS is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 1.8.9.
|
1.8.10 |
CVE7.1
NVDPending
|
| May 27, 2026 |
CVE-2026-42737
VikBooking Hotel Booking Engine & PMS: Filesystem traversal
VikBooking Hotel Booking Engine & PMS is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server. The published affected range is <= 1.8.9.
|
1.8.10 |
CVE8.6
NVDPending
|
| Dec 18, 2025 |
CVE-2025-49918
VikBooking Hotel Booking Engine & PMS: A security weakness
VikBooking Hotel Booking Engine & PMS is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.9
NVDPending
|
| Nov 06, 2025 |
CVE-2025-5803
VikBooking Hotel Booking Engine & PMS: A security weakness
VikBooking Hotel Booking Engine & PMS is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Mar 27, 2025 |
CVE-2025-22670
VikBooking Hotel Booking Engine & PMS: A security weakness
VikBooking Hotel Booking Engine & PMS is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Apr 18, 2024 |
CVE-2024-32563
VikBooking Hotel Booking Engine & PMS: Cross-site scripting
VikBooking Hotel Booking Engine & PMS is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE7.1
NVDPending
|
| Nov 09, 2023 |
CVE-2023-32501
Vikbooking: Cross-site request forgery
Vikbooking is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE4.3
NVD8.8
|
| May 23, 2023 |
CVE-2023-25707
Vikbooking: Cross-site request forgery
Vikbooking is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE6.3
NVD8.8
|
| Apr 06, 2023 |
CVE-2023-24396
Vikbooking: Cross-site scripting
Vikbooking is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.9
NVD4.8
|
| Apr 19, 2022 |
CVE-2022-27863
Vikbooking: Sensitive information exposure
Vikbooking is affected by sensitive information exposure. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can disclose data that should not be available to the caller.
|
See mitigation notes |
CVE5.3
NVD5.3
|
| Apr 19, 2022 |
CVE-2022-27862
Vikbooking: Dangerous file upload
Vikbooking is affected by dangerous file upload. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise.
|
See mitigation notes |
CVE9.8
NVD9.8
|