{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/vendors/vikbooking/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-15401"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["VikBooking Hotel Booking Engine \u0026 PMS plugin for WordPress (\u003c= 1.8.13)"],"_cs_severities":["high"],"_cs_tags":["wordpress","xss","web-vulnerability","stored-xss","cms"],"_cs_type":"threat","_cs_vendors":["VikBooking"],"content_html":"\u003cp\u003eA critical Stored Cross-Site Scripting (XSS) vulnerability, identified as CVE-2026-15401, has been discovered in the VikBooking Hotel Booking Engine \u0026amp; PMS plugin for WordPress, affecting all versions up to and including 1.8.13. This flaw stems from insufficient input sanitization and output escaping of the 'vbfX' parameter. Exploitation is possible by unauthenticated attackers who can inject arbitrary web scripts into pages. The vulnerability exists because the public-facing 'saveorder' task, responsible for storing the 'vbfX' custom-field value, lacks proper capability and authentication checks. This allows a malicious payload to be submitted without authentication and stored in the database. When a legitimate user subsequently accesses a page displaying the stored 'vbfX' value, the injected script executes in their browser, leading to potential data theft, session hijacking, or defacement. This poses a significant risk to websites using the vulnerable plugin.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn unauthenticated attacker identifies a WordPress website running a vulnerable version of the VikBooking Hotel Booking Engine \u0026amp; PMS plugin (\u0026lt;= 1.8.13).\u003c/li\u003e\n\u003cli\u003eThe attacker crafts a malicious JavaScript payload designed to perform actions like session hijacking, data exfiltration, or defacement.\u003c/li\u003e\n\u003cli\u003eThe attacker sends an unauthenticated HTTP POST request to the WordPress site's \u003ccode\u003eadmin-ajax.php\u003c/code\u003e endpoint.\u003c/li\u003e\n\u003cli\u003eIn the request body, the attacker includes \u003ccode\u003eaction=saveorder\u003c/code\u003e and embeds the crafted XSS payload within the \u003ccode\u003evbfX\u003c/code\u003e parameter.\u003c/li\u003e\n\u003cli\u003eDue to insufficient input validation, the vulnerable plugin processes and stores the malicious \u003ccode\u003evbfX\u003c/code\u003e content in the WordPress database without authentication.\u003c/li\u003e\n\u003cli\u003eA legitimate user (e.g., an administrator or a visitor viewing booking information) navigates to a page that renders the previously stored \u003ccode\u003evbfX\u003c/code\u003e custom field.\u003c/li\u003e\n\u003cli\u003eThe browser of the legitimate user executes the attacker's injected script, leading to compromise of the user's session, unauthorized actions, or other malicious outcomes.\u003c/li\u003e\n\u003cli\u003eThe attacker gains control over the victim's browser session, allowing for cookie theft, arbitrary actions on behalf of the victim, or content defacement.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-15401 allows unauthenticated attackers to inject persistent malicious web scripts into affected WordPress sites. When executed in a victim's browser, these scripts can lead to significant consequences, including the theft of sensitive user data (such as session cookies, allowing for session hijacking), website defacement, redirection to malicious sites, or the execution of arbitrary actions on behalf of the victim within the affected web application. For e-commerce or booking sites, this could result in fraudulent bookings, exposure of customer data, and severe reputational damage. The broad reach of WordPress plugins means a large number of potentially affected websites and users are at risk if the vulnerability is exploited in the wild.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch CVE-2026-15401 immediately by updating the VikBooking Hotel Booking Engine \u0026amp; PMS plugin for WordPress to version 1.8.14 or later.\u003c/li\u003e\n\u003cli\u003eDeploy the Sigma rule \u0026quot;Detects CVE-2026-15401 Exploitation - VikBooking XSS Payload Delivery\u0026quot; to your SIEM to detect attempted exploitation.\u003c/li\u003e\n\u003cli\u003eEnable comprehensive web server logging, specifically capturing HTTP POST requests, URI stems, and query parameters, to ensure data is available for the Sigma rule.\u003c/li\u003e\n\u003cli\u003eMonitor \u003ccode\u003ewebserver\u003c/code\u003e logs for suspicious POST requests to \u003ccode\u003eadmin-ajax.php\u003c/code\u003e containing XSS payload patterns in the \u003ccode\u003evbfX\u003c/code\u003e parameter, as outlined in the detection rule.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-24T10:18:13Z","date_published":"2026-07-24T10:18:13Z","id":"https://feed.craftedsignal.io/briefs/2026-07-vikbooking-xss/","summary":"The VikBooking Hotel Booking Engine \u0026 PMS plugin for WordPress versions up to and including 1.8.13 is vulnerable to Stored Cross-Site Scripting (XSS) via the 'vbfX' parameter, allowing unauthenticated attackers to inject arbitrary web scripts that execute when a user accesses an infected page.","title":"VikBooking Hotel Booking Engine \u0026 PMS Plugin Vulnerable to Stored Cross-Site Scripting (CVE-2026-15401)","url":"https://feed.craftedsignal.io/briefs/2026-07-vikbooking-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - VikBooking","version":"https://jsonfeed.org/version/1.1"}