Sceawere
Vulnerability Detail
CVE-2026-95684UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
VikBooking Stored XSS Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.2
- Creation Date
- 3h ago
- Vendor
- e4jvikwp
- Product
- VikBooking Hotel Booking Engine & PMS
- Attack Type
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'attachments[name]' Parameter in all versions up to, and including, 1.8.15 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.2",
"pubDate": "2026-10-10T07:16:42.200Z",
"pubdate": "2026-10-10T07:16:42.200Z",
"executiveSummary": "The VikBooking Hotel Booking Engine & PMS plugin for WordPress is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability affecting all versions up to and including 1.8.15.\nThis vulnerability originates from inadequate sanitization and output escaping of user-supplied data provided via the 'attachments[name]' parameter.\nThe flaw allows unauthenticated attackers to inject malicious JavaScript into the application's backend or frontend, which executes whenever a user visits the affected page.\nThe primary risk implications involve unauthorized actions performed on behalf of authenticated administrators, such as session hijacking, data exfiltration, or the injection of malicious content into the reservation management system.\nSuccessful exploitation requires no prior authentication, significantly increasing the risk profile for affected WordPress installations. Administrators are urged to update the plugin immediately to mitigate the potential for full administrative account takeover or unauthorized modification of booking data.",
"technicalDetails": "The vulnerability resides in the way the VikBooking Hotel Booking Engine & PMS handles the 'attachments[name]' parameter during file upload or management processes. Due to a lack of rigorous input validation and the absence of context-aware output encoding, the application allows the storage of arbitrary HTML or JavaScript payloads within the database.\nThe root cause is identified as an insufficient sanitization layer that permits special characters—such as script tags—to pass through the backend processes. When these malicious strings are retrieved from the database and rendered in the browser during an administrative session or a public-facing booking view, the victim's browser interprets the injected content as executable code.\nThe attack flow proceeds as follows: First, an unauthenticated attacker identifies the vulnerable endpoint responsible for processing reservation attachments. Second, the attacker crafts a malicious request by injecting a JavaScript payload into the 'attachments[name]' parameter. Third, the plugin improperly saves this payload into the WordPress database.\nFinally, when an administrator accesses the VikBooking management dashboard or a specific page where these attachment names are rendered, the injected script executes within the context of the administrator's session. This grants the attacker the same permissions as the compromised user session, potentially leading to unauthorized data access, the modification of hotel settings, or the deployment of secondary malware.\nAs the vulnerability does not require authentication, the attack vector is exposed to the public network. Any external actor can interact with the plugin's submission forms or API endpoints to place the payload. Post-exploitation impact is severe, as the attacker can perform actions that modify the reservation system's integrity or conduct lateral movement within the WordPress administrative environment by capturing session cookies or CSRF tokens."
}