CVE-2024-13616: VikBooking < 1.7.2 - Admin+ Stored XSS
The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.7.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example in multisite setup).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-13616?
CVE-2024-13616 has a high severity rating due to its potential for allowing stored cross-site scripting attacks.
How do I fix CVE-2024-13616?
To fix CVE-2024-13616, update the VikBooking Hotel Booking Engine & PMS plugin to version 1.7.2 or later.
Who is affected by CVE-2024-13616?
CVE-2024-13616 affects users of the VikBooking Hotel Booking Engine & PMS plugin versions prior to 1.7.2.
What type of attack does CVE-2024-13616 facilitate?
CVE-2024-13616 facilitates stored cross-site scripting (XSS) attacks by failing to sanitize and escape settings.
Can administrators mitigate CVE-2024-13616 without an update?
Administrators cannot effectively mitigate CVE-2024-13616 without updating to the patched version, as the vulnerability specifically affects high privilege user actions.