CVE-2026-95684: VikBooking Hotel Booking Engine & PMS <= 1.8.15 - Unauthenticated Stored Cross-Site Scripting via 'attachments[name]' Parameter
The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'attachments[name]' Parameter in all versions up to, and including, 1.8.15 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected Software
Event History
Frequently Asked Questions
Which deployments are affected?
All VikBooking Hotel Booking Engine & PMS plugin versions up to and including 1.8.15 are affected.
Does exploitation require an authenticated WordPress account or user interaction?
No. The vulnerability can be exploited by an unauthenticated attacker and does not require user interaction for injection; the stored script executes when someone later accesses the injected page.
What is the potential impact of successful exploitation?
An attacker can store arbitrary web scripts that run in the browser of users who view an affected page. The supplied severity vector indicates low confidentiality and integrity impact, with no availability impact.