CVE-2026-85127: VikBooking 1.8.8 - 1.8.14 - Unauthenticated Stored XSS via SVG Chat Attachment
The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.8.15 does not restrict the type of files unauthenticated visitors may attach to its live chat, nor sanitize their contents, allowing them to store active content which is executed in the context of an administrator viewing the conversation.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
VikBooking Hotel Booking Engine & PMS (WordPress plugin)to a version that resolves this vulnerability.Fixed in 1.8.15
Event History
Frequently Asked Questions
Who is exposed to exploitation?
Sites using the affected VikBooking WordPress plugin versions before 1.8.15 are exposed if the live chat attachment feature is available to unauthenticated visitors. An administrator who views a conversation containing a malicious attachment is the execution target.
What does an attacker need to exploit this issue?
The attacker only needs to be able to submit a live chat attachment as an unauthenticated visitor. They can upload active content, such as an SVG, that is stored and later executed when an administrator views the conversation.
Which versions are affected and what fixes the issue?
Versions 1.8.8 through 1.8.14 are affected. Updating to version 1.8.15 or later addresses the issue.