{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3avikwpvikbookingwordpress/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:vikwp:vikbooking:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-95684"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["VikBooking Hotel Booking Engine \u0026 PMS (\u003c= 1.8.15)"],"_cs_severities":["high"],"_cs_tags":["web-application","wordpress","xss"],"_cs_type":"advisory","_cs_vendors":["VikWP"],"content_html":"\u003cp\u003eThe VikBooking Hotel Booking Engine \u0026amp; PMS plugin for WordPress, in all versions up to and including 1.8.15, is vulnerable to a Stored Cross-Site Scripting (XSS) vulnerability. This flaw exists due to insufficient input sanitization and output escaping on the 'attachments[name]' parameter. Unauthenticated attackers can exploit this vulnerability to inject arbitrary web scripts into the application. When a victim, such as an administrator or another user, accesses the page where the malicious script is stored, the browser executes the script in the context of the user session. This can lead to unauthorized administrative actions, session hijacking, or redirection to malicious sites. Because the plugin is used for hotel booking management, this vulnerability poses a high risk to businesses managing guest and administrative data within the WordPress dashboard.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to execute arbitrary JavaScript in the context of a legitimate user's browser session. In a WordPress environment, this typically results in account takeover, unauthorized modification of plugin settings, or exfiltration of sensitive booking data. The target scope includes any WordPress instance running vulnerable versions of VikBooking.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eImmediately update the VikBooking Hotel Booking Engine \u0026amp; PMS plugin to a version beyond 1.8.15.\u003c/li\u003e\n\u003cli\u003eAudit WordPress dashboard access logs for suspicious POST requests targeting plugin attachment endpoints.\u003c/li\u003e\n\u003cli\u003eImplement a Web Application Firewall (WAF) rule to inspect input parameters containing HTML or script tags directed at the plugin's attachment functionality.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-10-10T07:52:45Z","date_published":"2026-10-10T07:52:45Z","id":"https://feed.craftedsignal.io/briefs/2026-10-vikbooking-xss/","summary":"The VikBooking Hotel Booking Engine \u0026 PMS plugin for WordPress up to version 1.8.15 contains a Stored XSS vulnerability in the 'attachments[name]' parameter that allows unauthenticated attackers to inject malicious scripts.","title":"Stored Cross-Site Scripting in VikBooking WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-10-vikbooking-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:vikwp:vikbooking:*:*:*:*:*:wordpress:*:*","version":"https://jsonfeed.org/version/1.1"}