CVE-2022-1528: VikBooking < 1.5.9 - Reflected Cross-Site Scripting
Published May 30, 2022
·Updated
The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.5.9 does not escape the current URL before putting it back in a JavaScript context, leading to a Reflected Cross-Site Scripting
Affected Software
1 affected component
vikwp Vik Booking Wordpress<1.5.9
Event History
May 30, 2022
CVE Published
via MITRE·08:35 AM
Data Sourced
via MITRE·08:35 AM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2022-1528?
CVE-2022-1528 is a vulnerability found in the VikBooking Hotel Booking Engine & PMS WordPress plugin before version 1.5.9.
2
What is the severity of CVE-2022-1528?
CVE-2022-1528 has a severity rating of medium, with a CVSS score of 6.1.
3
How does CVE-2022-1528 affect the VikBooking plugin?
CVE-2022-1528 allows for Reflected Cross-Site Scripting (XSS) attacks in the VikBooking plugin before version 1.5.9.
4
What software versions are affected by CVE-2022-1528?
The VikBooking Hotel Booking Engine & PMS WordPress plugin versions up to and excluding 1.5.9 are affected by CVE-2022-1528.
5
Is there a fix available for CVE-2022-1528?
Yes, updating the VikBooking plugin to version 1.5.9 or newer will fix the vulnerability.