VikBooking Hotel Booking Engine & PMS: Stored XSS through booking chat attachments
An unauthenticated attacker can submit active content as a chat attachment that executes when an administrator views it. The issue begins in version 1.8.8. The export does not disclose the attachment field or handler and does not establish server-side PHP execution. Affected versions reported by the CNA: 1.8.8 to < 1.8.15. The export identifies 1.8.15 as fixed.
- Component
- VikBooking Hotel Booking Engine & PMS
- Plugin slug
vikbooking- Affected
- 1.8.8 to < 1.8.15
- Safe version
1.8.15- Published
- Sep 18, 2026
This CVE was published Sep 18, 2026 and is one of 19 known issues for this plugin.
Update, patch or deactivate.
The authoritative export identifies 1.8.15 as fixed. Update to that release or a later supported version. Restrict permitted attachment types, validate content independently of filenames, and serve untrusted files with safe content types and disposition outside executable contexts.
A safe version is available, so updating to that version or later is the preferred remediation. If an immediate update is not practical, consider a targeted application patch or temporarily restricting the affected functionality.
Deactivate only when warranted by your risk profile, or when advised by your hosting provider in the limited circumstances where the vulnerability cannot otherwise be mitigated. If you’re unsure which action is appropriate, contact Fused or your hosting provider for guidance.
Technical description
The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.8.15 does not restrict the type of files unauthenticated visitors may attach to its live chat, nor sanitize their contents, allowing them to store active content which is executed in the context of an administrator viewing the conversation.
CVE / CNA vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H