Impact
This CVE documents a Cross‑Site Request Forgery flaw classified as CWE‑352 in the e4jvikwp VikBooking Hotel Booking Engine & PMS plugin. The vulnerability permits an attacker to construct a forged request that induces the server to interpret a path traversal payload, leading to the deletion of arbitrary files on the web server. The description does not explicitly, so we infer that a non‑authenticated or authenticated user might be able to trigger the deletion, depending on the site’s user permissions.
Affected Systems
Affected system is any WordPress installation running’s VikBooking Hotel Booking Engine & PMS plugin at version 1.8.12 or earlier. The vendor explicitly states that the issue exists from “n/a” through 1.8.12, meaning all releases up to that point are vulnerable.
Risk and Exploitability
The high CVSS score of 7.4 indicates that the vulnerability can substantially impact confidentiality, integrity, and availability if exploited. With an EPSS score of less than 1% the current likelihood of exploitation is low, and the vulnerability is not included in the CISA KEV catalog, reducing the immediate threat of known exploits. Because the flaw is a CSRF attack that leads to arbitrary file deletion, an attacker only needs to lure a site user or an authenticated administrator to submit a crafted request; the absence of a documented authentication requirement suggests the potential for exploitation by both authenticated and possibly unauthenticated users.
OpenCVE Enrichment