Impact
The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to a reflected Cross‑Site Scripting flaw caused by inadequate sanitization and escaping of the 'category_id' parameter. An unauthenticated attacker can craft a URL that, when clicked by a victim, injects arbitrary JavaScript into a hidden element that executes in browsers supporting access keys, giving the attacker the ability to run code in the victim's browser, potentially leading to session hijacking, keylogging, or defacement.
Affected Systems
All installations of the VikBooking Hotel Booking Engine & PMS plugin for WordPress that are version 1.8.13 or earlier are affected. Any WordPress site deploying that plugin version is at risk.
Risk and Exploitability
The CVSS v3.1 score is 6.1, indicating medium severity. The EPSS score of less than 1 % suggests a very low likelihood of real‑world exploitation, especially since the payload is delivered via a hidden element that only runs in browsers that support access keys. The flaw is not listed in the CISA KEV catalog, further reducing the probability of widespread targeting. Nonetheless, because the vulnerability can be triggered by a simple click on a crafted link, it remains a legitimate threat for publicly accessible WordPress sites.
OpenCVE Enrichment