CVE-2022-1408: VikBooking Hotel Booking Engine & PMS < 1.5.8 - Admin+ Stored Cross-Site Scripting
The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.5.8 does not escape various settings before outputting them in attributes, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfilteredhtml is disallowed
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-1408?
CVE-2022-1408 is a vulnerability in the VikBooking Hotel Booking Engine & PMS WordPress plugin that allows high privilege users to perform Cross-Site Scripting attacks.
How severe is CVE-2022-1408?
CVE-2022-1408 has a severity level of medium with a CVSS score of 4.8.
What software versions are affected by CVE-2022-1408?
Versions of the VikBooking Hotel Booking Engine & PMS WordPress plugin prior to 1.5.8 are affected by CVE-2022-1408.
How can CVE-2022-1408 be exploited?
CVE-2022-1408 can be exploited by high privilege users, such as admin, to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed.
Is there a fix available for CVE-2022-1408?
Yes, the fix for CVE-2022-1408 is to update the VikBooking Hotel Booking Engine & PMS WordPress plugin to version 1.5.8 or later.