CVE-2022-27863: WordPress VikBooking Hotel Booking Engine & PMS plugin <= 1.5.3 - Sensitive Data Exposure vulnerability
Sensitive Information Exposure in E4J s.r.l. VikBooking Hotel Booking Engine & PMS plugin <= 1.5.3 on WordPress allows attackers to get the booking data by guessing / brute-forcing easy predictable booking IDs via search POST requests.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2022-27863?
CVE-2022-27863 is a vulnerability that allows attackers to obtain sensitive booking data by guessing or brute-forcing easy predictable booking IDs via search POST requests in the E4J s.r.l. VikBooking Hotel Booking Engine & PMS plugin <= 1.5.3 on WordPress.
How severe is CVE-2022-27863?
CVE-2022-27863 has a severity rating of medium with a severity value of 5.3.
What software is affected by CVE-2022-27863?
The E4J s.r.l. VikBooking Hotel Booking Engine & PMS plugin <= 1.5.3 on WordPress is affected by CVE-2022-27863.
How can attackers exploit CVE-2022-27863?
Attackers can exploit CVE-2022-27863 by guessing or brute-forcing easy predictable booking IDs via search POST requests.
Are there any references for CVE-2022-27863?
Yes, you can find references for CVE-2022-27863 at the following links: [link1](https://patchstack.com/database/vulnerability/vikbooking/wordpress-vikbooking-hotel-booking-engine-pms-plugin-1-5-3-sensitive-data-exposure-vulnerability) and [link2](https://wordpress.org/plugins/vikbooking/#developers).