CVE-2026-15401

e4j · VikBooking Hotel Booking Engine & PMS

The VikBooking Hotel Booking Engine & PMS plugin for WordPress is susceptible to a stored cross-site scripting (XSS) vulnerability via the vbfX parameter.

Executive summary

A high-severity stored cross-site scripting vulnerability in the VikBooking Hotel Booking Engine & PMS plugin allows unauthenticated attackers to inject malicious scripts into the application.

Vulnerability

The plugin fails to properly sanitize user-supplied input in the vbfX parameter, leading to a stored cross-site scripting (CWE-79) vulnerability. This vulnerability is accessible to unauthenticated attackers.

Business impact

Successful exploitation of this XSS vulnerability can lead to the execution of arbitrary scripts in the context of a victim's browser session. This could result in unauthorized administrative actions, session hijacking, or the theft of sensitive user data, severely compromising the security and reputation of the booking platform. The CVSS score of 7.2 highlights the significant impact associated with this flaw.

Remediation

Immediate Action: Update the VikBooking Hotel Booking Engine & PMS plugin to version 1.8.14 or later to ensure proper input sanitization.

Proactive Monitoring: Monitor site traffic and application logs for suspicious payloads or anomalous characters commonly associated with XSS attacks.

Compensating Controls: Utilize a Web Application Firewall (WAF) to detect and block malicious script injection attempts targeting the plugin's input parameters.

Exploitation status

Public Exploit Available: No

Analyst recommendation

To mitigate the risk of cross-site scripting, administrators must update the VikBooking plugin immediately. Failure to apply the patch leaves the application vulnerable to session hijacking and other malicious activities that could result in significant business disruption.