Impact
The vulnerability resides in the VikBooking Hotel Booking Engine & PMS plugin for WordPress and allows an attacker to embed malicious scripts into the custom field parameter vbfX. Because no input validation or output escaping is performed, the stored payload is rendered when other users load the affected page. This allows arbitrary script execution in the context of users who view the injected content. The weakness aligns with CWE‑79: Improper Neutralization of Input During Web Page Generation.
Affected Systems
VikBooking Hotel Booking Engine & PMS plugin for WordPress versions up to and including 1.8.13 are affected. All WordPress sites that have a vulnerable version of the plugin installed are at risk.
Risk and Exploitability
The CVSS score of 7.2 indicates a high‑severity vulnerability. The likely exploitation path involves an unauthenticated request to the publicly accessible saveorder endpoint, which is inferred from the description of the unprotected task. The EPSS score of less than 1% suggests that exploitation in the wild is currently low, and the vulnerability is not listed in CISA’s KEV catalog.
OpenCVE Enrichment