Description
Missing Authorization vulnerability in e4jvikwp VikBooking Hotel Booking Engine & PMS vikbooking.This issue affects VikBooking Hotel Booking Engine & PMS: from n/a through <= 1.8.2.
Published: 2025-11-06
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a missing authorization check in the VikBooking plugin for WordPress. When this flaw is present, users with limited privileges can access or modify administrative functions that should be restricted. The flaw is categorized as a broken access control (CWE‑862). The impact is that attackers could potentially view, edit or delete booking data, cancel reservations, or change booking settings, compromising data confidentiality and integrity. The description does not indicate remote code execution or denial of service but clearly permits unauthorized privilege escalation.

Affected Systems

The affected product is the VikBooking Hotel Booking Engine & PMS plugin for WordPress developed by e4jvikwp. All installations running versions from the first public release up to and including 1.8.2 are vulnerable. No specific distribution or operating system restrictions are indicated.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate risk. The EPSS score is below 1%, suggesting a low probability of exploitation at this point. The vulnerability is not listed in the CISA KEV catalog. Because the flaw involves a missing authorization check, the likely attack vector is an authenticated user who is able to elevate privileges by accessing restricted administrative endpoints. As no further technical details are supplied, it is inferred that the attacker would need access to a regular user account, after which the broken check would allow unauthorized actions.

Generated by OpenCVE AI on April 29, 2026 at 23:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the VikBooking plugin to the latest version, ensuring the fix for the access control issue is applied.
  • If an upgrade is not immediately possible, restrict access to the plugin's administrative interfaces by limiting the allowed IP addresses or using a WAF rule.
  • Review user role definitions and ensure that only administrators have permission to use booking management features; enforce proper role checks or disable misleading capabilities manually.
  • Enable logging and monitor for any attempts to access administrative functions from non‑administrative accounts.

Generated by OpenCVE AI on April 29, 2026 at 23:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Apr 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Thu, 13 Nov 2025 11:30:00 +0000


Thu, 13 Nov 2025 10:45:00 +0000


Mon, 10 Nov 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 06 Nov 2025 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Vikwp
Vikwp vikbooking Hotel Booking Engine & Pms
Wordpress
Wordpress wordpress
Vendors & Products Vikwp
Vikwp vikbooking Hotel Booking Engine & Pms
Wordpress
Wordpress wordpress

Thu, 06 Nov 2025 16:00:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in e4jvikwp VikBooking Hotel Booking Engine & PMS vikbooking.This issue affects VikBooking Hotel Booking Engine & PMS: from n/a through <= 1.8.2.
Title WordPress VikBooking Hotel Booking Engine & PMS plugin <= 1.8.2 - Broken Access Control vulnerability
Weaknesses CWE-862
References

Subscriptions

Vikwp Vikbooking Hotel Booking Engine & Pms
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:13:40.872Z

Reserved: 2025-06-06T10:04:42.368Z

Link: CVE-2025-5803

cve-icon Vulnrichment

Updated: 2025-11-10T19:25:52.297Z

cve-icon NVD

Status : Deferred

Published: 2025-11-06T16:16:02.763

Modified: 2026-04-27T19:16:17.220

Link: CVE-2025-5803

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T23:30:22Z

Weaknesses