CVE-2026-42762: WordPress VikBooking Hotel Booking Engine & PMS plugin <= 1.8.9 - Cross Site Scripting (XSS) vulnerability
Published May 27, 2026
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e4jvikwp VikBooking Hotel Booking Engine & PMS vikbooking allows DOM-Based XSS.This issue affects VikBooking Hotel Booking Engine & PMS: from n/a through <= 1.8.9.
Affected Software
1 affected component
e4jvikwp VikBooking Hotel Booking Engine & PMS<=1.8.9
Event History
May 27, 2026
CVE Published
via MITRE·09:49 AM
Data Sourced
via MITRE·09:49 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-42762?
The severity of CVE-2026-42762 is classified as high, with a score of 7.1.
2
What type of vulnerability is CVE-2026-42762?
CVE-2026-42762 is a Cross-Site Scripting (XSS) vulnerability.
3
How do I fix CVE-2026-42762?
To fix CVE-2026-42762, update the VikBooking Hotel Booking Engine & PMS plugin to version 1.9 or later.
4
How does CVE-2026-42762 affect the system?
CVE-2026-42762 allows for DOM-Based XSS, which could enable attackers to execute malicious scripts in the context of a user's browser.
5
Which versions of the VikBooking plugin are affected by CVE-2026-42762?
CVE-2026-42762 affects VikBooking Hotel Booking Engine & PMS plugin versions up to and including 1.8.9.