CVE-2026-85127
8.8WordPress · VikBooking Hotel Booking Engine & PMS
The VikBooking Hotel Booking Engine & PMS plugin allows unauthenticated users to upload malicious files via live chat, leading to stored Cross-Site Scripting (XSS) when viewed by an administrator.
Executive summary
A critical stored Cross-Site Scripting vulnerability in the VikBooking Hotel Booking Engine & PMS plugin allows unauthenticated attackers to execute arbitrary scripts within an administrator session.
Vulnerability
This vulnerability is a stored Cross-Site Scripting (XSS) flaw caused by a lack of file type restriction and sanitization in the live chat attachment feature. Unauthenticated attackers can upload malicious files that execute in the browser context of an administrator who views the conversation history.
Business impact
The ability for an unauthenticated attacker to execute code in an administrator context poses a severe risk to site integrity and security. A successful exploit could lead to full administrative account takeover, unauthorized access to sensitive booking data, and potential redirection of customers to malicious domains. The CVSS score of 8.8 reflects the high potential for impact on confidentiality, integrity, and availability within the WordPress environment.
Remediation
Immediate Action: Update the VikBooking Hotel Booking Engine & PMS plugin to version 1.8.15 or later immediately.
Proactive Monitoring: Review administrative audit logs for unusual activity or unauthorized changes made to site settings or user accounts.
Compensating Controls: Implement a Web Application Firewall (WAF) with rules configured to block malicious file uploads and detect common XSS patterns in incoming traffic.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the severity of this vulnerability and the potential for complete administrative compromise, users of the VikBooking plugin must prioritize this update. Administrators should verify that the plugin has been updated to version 1.8.15 across all affected installations to mitigate the risk of unauthorized script execution.
More WordPress CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- Analyst report written
- Published in the daily brief high section
Sources
Originally found and disclosed by anhdung1329, with WPScan (coordinator), per the CVE Program record.