CVE-2025-49918: WordPress VikBooking Hotel Booking Engine & PMS plugin <= 1.8.2 - Sensitive Data Exposure vulnerability
Insertion of Sensitive Information Into Sent Data vulnerability in e4jvikwp VikBooking Hotel Booking Engine & PMS vikbooking allows Retrieve Embedded Sensitive Data.This issue affects VikBooking Hotel Booking Engine & PMS: from n/a through <= 1.8.2.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-49918?
CVE-2025-49918 is classified as a medium severity vulnerability due to its potential for sensitive data exposure.
How do I fix CVE-2025-49918?
To remediate CVE-2025-49918, update the VikBooking Hotel Booking Engine & PMS plugin to a version later than 1.8.2.
What specific data is exposed by CVE-2025-49918?
CVE-2025-49918 allows the retrieval of embedded sensitive data during data transmission.
Which versions of the VikBooking plugin are affected by CVE-2025-49918?
Versions of the VikBooking Hotel Booking Engine & PMS plugin up to and including 1.8.2 are affected by CVE-2025-49918.
What type of vulnerability is CVE-2025-49918 classified as?
CVE-2025-49918 is classified as a Sensitive Data Exposure vulnerability.