rootpwn

critical · CVSS v3 9.1

CVE-2026-85127

The VikBooking Hotel Booking Engine & PMS WordPress plugin before version 1.8.15 lacks proper file type restrictions and sanitization for un

Overview

The VikBooking Hotel Booking Engine & PMS WordPress plugin before version 1.8.15 lacks proper file type restrictions and sanitization for unauthenticated live chat attachments. This flaw allows malicious users to store active content that executes within the browser context of an administrator reviewing the conversation.

Description

The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.8.15 does not restrict the type of files unauthenticated visitors may attach to its live chat, nor sanitize their contents, allowing them to store active content which is executed in the context of an administrator viewing the conversation.

Impact

The vulnerability primarily impacts the integrity and confidentiality of the WordPress site by enabling stored cross-site scripting (XSS) attacks. Because the payload executes in the context of an administrator, attackers could potentially escalate privileges, compromise administrative sessions, or manipulate site content. Website administrators and businesses relying on the affected plugin for booking management are directly at risk.

Remediation

Update the VikBooking Hotel Booking Engine & PMS plugin to version 1.8.15 or later where file validation and sanitization controls are implemented. Implement strict file upload policies and web application firewall (WAF) rules to inspect live chat attachment traffic for malicious scripts. Monitor administrator account activities and enforce multi-factor authentication (MFA) to mitigate potential session hijacking attempts.

Risk context

This vulnerability carries a critical CVSS score of 9.1 due to the combination of unauthenticated access and high-privilege execution context. Immediate patching is strongly recommended to eliminate the vector for administrative session compromise.

Affected products

  • E4J s.r.l. VikBooking Hotel Booking Engine & PMS WordPress plugin

Scores

Severity
critical
CVSS v2
6.4
CVSS v3
9.1
CVSS v4
EPSS

cve wordpress plugin stored-xss unauthenticated file-upload critical

← All CVEs