CVE-2026-42737: WordPress VikBooking Hotel Booking Engine & PMS plugin <= 1.8.9 - Arbitrary File Deletion vulnerability
Published May 27, 2026
·Updated
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in e4jvikwp VikBooking Hotel Booking Engine & PMS vikbooking allows Path Traversal.This issue affects VikBooking Hotel Booking Engine & PMS: from n/a through <= 1.8.9.
Affected Software
1 affected component
e4jvikwp VikBooking Hotel Booking Engine & PMS<=1.8.9
Event History
May 27, 2026
CVE Published
via MITRE·09:49 AM
Data Sourced
via MITRE·09:49 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-42737?
CVE-2026-42737 has a high severity rating of 8.6.
2
How does CVE-2026-42737 affect WordPress VikBooking Hotel Booking Engine & PMS plugin?
CVE-2026-42737 allows for arbitrary file deletion through a path traversal vulnerability in versions up to and including 1.8.9.
3
What is the impact of exploiting CVE-2026-42737?
Exploitation of CVE-2026-42737 can lead to unauthorized file deletion on the server.
4
How can I fix CVE-2026-42737?
To fix CVE-2026-42737, upgrade the VikBooking Hotel Booking Engine & PMS plugin to a version beyond 1.8.9.
5
Is there a workaround for CVE-2026-42737 if I cannot update immediately?
There are no recommended workarounds for CVE-2026-42737 other than upgrading to a secure version.