CPE
The VikBooking Hotel Booking Engine & PMS plugin for WordPress up to version 1.8.15 contains a Stored XSS vulnerability in the 'attachments[name]' parameter that allows unauthenticated attackers to inject malicious scripts.