CVE-2025-22670: WordPress VikBooking Hotel Booking Engine & PMS plugin <= 1.7.2 - CSRF to Settings Change vulnerability
Missing Authorization vulnerability in e4jvikwp VikBooking Hotel Booking Engine & PMS allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects VikBooking Hotel Booking Engine & PMS: from n/a through 1.7.2.
Other sources
Missing Authorization vulnerability in e4jvikwp VikBooking Hotel Booking Engine & PMS vikbooking allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects VikBooking Hotel Booking Engine & PMS: from n/a through <= 1.7.2.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-22670?
CVE-2025-22670 is classified as a missing authorization vulnerability affecting versions of VikBooking Hotel Booking Engine & PMS up to 1.7.2.
How do I fix CVE-2025-22670?
To fix CVE-2025-22670, ensure that proper access control security levels are configured and consider updating to the latest version of VikBooking.
What causes CVE-2025-22670?
CVE-2025-22670 is caused by incorrectly configured access control settings that allow unauthorized actions within the VikBooking system.
Which versions are affected by CVE-2025-22670?
CVE-2025-22670 affects the VikBooking Hotel Booking Engine & PMS from versions up to and including 1.7.2.
Can CVE-2025-22670 be exploited remotely?
Yes, CVE-2025-22670 can potentially be exploited remotely due to the lack of proper authorization checks.