CVE-2026-57723: WordPress VikBooking Hotel Booking Engine & PMS plugin <= 1.8.12 - CSRF to Arbitrary File Deletion vulnerability
Cross-Site Request Forgery (CSRF) vulnerability in e4jvikwp VikBooking Hotel Booking Engine & PMS allows Path Traversal.
This issue affects VikBooking Hotel Booking Engine & PMS: from n/a through 1.8.12.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress VikBooking Hotel Booking Engine & PMS Pluginto a version that resolves this vulnerability.Fixed in 1.8.13
Event History
Frequently Asked Questions
What is the severity of CVE-2026-57723?
The severity of CVE-2026-57723 is high, with a score of 7.4.
How do I fix CVE-2026-57723?
To fix CVE-2026-57723, update the VikBooking Hotel Booking Engine & PMS plugin to version 1.8.13 or later.
What type of vulnerability is CVE-2026-57723?
CVE-2026-57723 is a Cross-Site Request Forgery (CSRF) vulnerability leading to arbitrary file deletion.
Which versions of the software are affected by CVE-2026-57723?
CVE-2026-57723 affects VikBooking Hotel Booking Engine & PMS from an unspecified version up to 1.8.12.
What are the potential consequences of exploiting CVE-2026-57723?
Exploiting CVE-2026-57723 could allow an attacker to delete arbitrary files from the affected server.