<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:vikwp:vikbooking:*:*:*:*:*:wordpress:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3avikwpvikbookingwordpress/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sat, 10 Oct 2026 07:52:45 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3avikwpvikbookingwordpress/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Stored Cross-Site Scripting in VikBooking WordPress Plugin</title><link>https://feed.craftedsignal.io/briefs/2026-10-vikbooking-xss/</link><pubDate>Sat, 10 Oct 2026 07:52:45 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-vikbooking-xss/</guid><description>The VikBooking Hotel Booking Engine &amp; PMS plugin for WordPress up to version 1.8.15 contains a Stored XSS vulnerability in the 'attachments[name]' parameter that allows unauthenticated attackers to inject malicious scripts.</description><content:encoded><![CDATA[<p>The VikBooking Hotel Booking Engine &amp; PMS plugin for WordPress, in all versions up to and including 1.8.15, is vulnerable to a Stored Cross-Site Scripting (XSS) vulnerability. This flaw exists due to insufficient input sanitization and output escaping on the 'attachments[name]' parameter. Unauthenticated attackers can exploit this vulnerability to inject arbitrary web scripts into the application. When a victim, such as an administrator or another user, accesses the page where the malicious script is stored, the browser executes the script in the context of the user session. This can lead to unauthorized administrative actions, session hijacking, or redirection to malicious sites. Because the plugin is used for hotel booking management, this vulnerability poses a high risk to businesses managing guest and administrative data within the WordPress dashboard.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows unauthenticated attackers to execute arbitrary JavaScript in the context of a legitimate user's browser session. In a WordPress environment, this typically results in account takeover, unauthorized modification of plugin settings, or exfiltration of sensitive booking data. The target scope includes any WordPress instance running vulnerable versions of VikBooking.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Immediately update the VikBooking Hotel Booking Engine &amp; PMS plugin to a version beyond 1.8.15.</li>
<li>Audit WordPress dashboard access logs for suspicious POST requests targeting plugin attachment endpoints.</li>
<li>Implement a Web Application Firewall (WAF) rule to inspect input parameters containing HTML or script tags directed at the plugin's attachment functionality.</li>
</ol>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>web-application</category><category>wordpress</category><category>xss</category></item></channel></rss>