Sceawere
Vulnerability Detail
CVE-2026-95591UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Reflected XSS in VikBooking Plugin
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.1
- Creation Date
- 3h ago
- Vendor
- e4jvikwp
- Product
- VikBooking Hotel Booking Engine & PMS
- Attack Type
- Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e4jvikwp VikBooking Hotel Booking Engine & PMS vikbooking allows Reflected XSS.This issue affects VikBooking Hotel Booking Engine & PMS: from n/a through 1.8.14.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.1",
"pubDate": "2026-10-09T10:16:42.237Z",
"pubdate": "2026-10-09T10:16:42.237Z",
"executiveSummary": "The VikBooking Hotel Booking Engine & PMS plugin for WordPress is susceptible to a Reflected Cross-Site Scripting (XSS) vulnerability. This vulnerability arises from improper neutralization of user-supplied input during web page generation, allowing an attacker to inject and execute arbitrary JavaScript within the context of a victim's browser session.\nThe flaw affects versions from n/a through 1.8.14. Successful exploitation requires a user to interact with a crafted malicious link. The impact of this vulnerability includes potential session hijacking, unauthorized actions performed on behalf of the authenticated user, and the theft of sensitive session cookies or personal data handled by the booking engine.\nRisk implications are significant for hotel management platforms where administrative sessions or customer booking details may be targeted. The vulnerability does not require authentication to exploit, relying instead on social engineering to entice a victim to click the malicious URL.\nTo mitigate this risk, it is recommended to update the plugin to the latest version if available and implement robust input sanitization and output encoding routines within the application logic.",
"technicalDetails": "The vulnerability is categorized as CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'). The root cause resides in the lack of adequate output encoding or input validation when processing parameters provided to the VikBooking plugin's request handlers.\nThe attack flow initiates when an attacker crafts a malicious URL containing a payload designed to break out of the HTML document context. By injecting script tags or event handlers (e.g., onerror, onload) into a parameter reflected by the application without proper contextual escaping, the attacker forces the victim's browser to execute the payload as part of the document structure.\nSince the VikBooking component processes these parameters dynamically to generate responses, the unsanitized input is rendered directly into the HTML source code. When the victim accesses the crafted link, their browser treats the reflected input as legitimate script or HTML code, granting the attacker the same origin privileges associated with the site domain.\nThe exploitation process follows these steps: 1. Identification of an input vector within the VikBooking interface that reflects data back to the user; 2. Crafting a URL containing a malicious JavaScript payload; 3. Delivering the URL to an authenticated user (such as a site administrator or booking agent) via phishing or social engineering; 4. Execution of the payload upon the user clicking the link. Once executed, the malicious script can access Document Object Model (DOM) elements, perform unauthorized requests via XMLHttpRequest or the Fetch API, or exfiltrate session identifiers to an external server controlled by the attacker.\nThis vulnerability is present in versions up to 1.8.14 and is exploitable over the network without the attacker possessing valid system credentials. The post-exploitation impact allows for full client-side control within the context of the affected web page, potentially leading to administrative account takeover if the victim has elevated privileges in the WordPress environment."
}