Sceawere

Vulnerability Detail

CVE-2026-95591UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Reflected XSS in VikBooking Plugin

Vulnerability Metadata

Severity
High
Score / CVSS
7.1
Creation Date
3h ago
Vendor
e4jvikwp
Product
VikBooking Hotel Booking Engine & PMS
Attack Type
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e4jvikwp VikBooking Hotel Booking Engine & PMS vikbooking allows Reflected XSS.This issue affects VikBooking Hotel Booking Engine & PMS: from n/a through 1.8.14.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.1",
  "pubDate": "2026-10-09T10:16:42.237Z",
  "pubdate": "2026-10-09T10:16:42.237Z",
  "executiveSummary": "The VikBooking Hotel Booking Engine & PMS plugin for WordPress is susceptible to a Reflected Cross-Site Scripting (XSS) vulnerability. This vulnerability arises from improper neutralization of user-supplied input during web page generation, allowing an attacker to inject and execute arbitrary JavaScript within the context of a victim's browser session.\nThe flaw affects versions from n/a through 1.8.14. Successful exploitation requires a user to interact with a crafted malicious link. The impact of this vulnerability includes potential session hijacking, unauthorized actions performed on behalf of the authenticated user, and the theft of sensitive session cookies or personal data handled by the booking engine.\nRisk implications are significant for hotel management platforms where administrative sessions or customer booking details may be targeted. The vulnerability does not require authentication to exploit, relying instead on social engineering to entice a victim to click the malicious URL.\nTo mitigate this risk, it is recommended to update the plugin to the latest version if available and implement robust input sanitization and output encoding routines within the application logic.",
  "technicalDetails": "The vulnerability is categorized as CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'). The root cause resides in the lack of adequate output encoding or input validation when processing parameters provided to the VikBooking plugin's request handlers.\nThe attack flow initiates when an attacker crafts a malicious URL containing a payload designed to break out of the HTML document context. By injecting script tags or event handlers (e.g., onerror, onload) into a parameter reflected by the application without proper contextual escaping, the attacker forces the victim's browser to execute the payload as part of the document structure.\nSince the VikBooking component processes these parameters dynamically to generate responses, the unsanitized input is rendered directly into the HTML source code. When the victim accesses the crafted link, their browser treats the reflected input as legitimate script or HTML code, granting the attacker the same origin privileges associated with the site domain.\nThe exploitation process follows these steps: 1. Identification of an input vector within the VikBooking interface that reflects data back to the user; 2. Crafting a URL containing a malicious JavaScript payload; 3. Delivering the URL to an authenticated user (such as a site administrator or booking agent) via phishing or social engineering; 4. Execution of the payload upon the user clicking the link. Once executed, the malicious script can access Document Object Model (DOM) elements, perform unauthorized requests via XMLHttpRequest or the Fetch API, or exfiltrate session identifiers to an external server controlled by the attacker.\nThis vulnerability is present in versions up to 1.8.14 and is exploitable over the network without the attacker possessing valid system credentials. The post-exploitation impact allows for full client-side control within the context of the affected web page, potentially leading to administrative account takeover if the victim has elevated privileges in the WordPress environment."
}
CVE-2026-95591: Reflected XSS in VikBooking Plugin (HIGH Severity, CVSS: 7.1) | Sceawere