Description
Cross-Site Request Forgery (CSRF) vulnerability in e4jvikwp VikBooking Hotel Booking Engine & PMS allows Path Traversal.

This issue affects VikBooking Hotel Booking Engine & PMS: from n/a through 1.8.12.
Published: 2026-07-01
Score: 7.4 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This CVE documents a Cross‑Site Request Forgery flaw classified as CWE‑352 in the e4jvikwp VikBooking Hotel Booking Engine & PMS plugin. The vulnerability permits an attacker to construct a forged request that induces the server to interpret a path traversal payload, leading to the deletion of arbitrary files on the web server. The description does not explicitly, so we infer that a non‑authenticated or authenticated user might be able to trigger the deletion, depending on the site’s user permissions.

Affected Systems

Affected system is any WordPress installation running’s VikBooking Hotel Booking Engine & PMS plugin at version 1.8.12 or earlier. The vendor explicitly states that the issue exists from “n/a” through 1.8.12, meaning all releases up to that point are vulnerable.

Risk and Exploitability

The high CVSS score of 7.4 indicates that the vulnerability can substantially impact confidentiality, integrity, and availability if exploited. With an EPSS score of less than 1% the current likelihood of exploitation is low, and the vulnerability is not included in the CISA KEV catalog, reducing the immediate threat of known exploits. Because the flaw is a CSRF attack that leads to arbitrary file deletion, an attacker only needs to lure a site user or an authenticated administrator to submit a crafted request; the absence of a documented authentication requirement suggests the potential for exploitation by both authenticated and possibly unauthenticated users.

Generated by OpenCVE AI on July 17, 2026 at 12:22 UTC.

Remediation

Vendor Solution

Update the WordPress VikBooking Hotel Booking Engine & PMS Plugin to the latest available version (at least 1.8.13).


OpenCVE Recommended Actions

  • Update the VikBooking plugin to version 1.8.13 or later.
  • Take a full backup of the WordPress site before applying the update to enable immediate rollback if the update causes issues.
  • After the update, perform a quick functional test of the file deletion feature to confirm that it no longer accepts arbitrary paths, and monitor file‑system logs for any suspicious deletion activity.

Generated by OpenCVE AI on July 17, 2026 at 12:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 01 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in e4jvikwp VikBooking Hotel Booking Engine & PMS allows Path Traversal. This issue affects VikBooking Hotel Booking Engine & PMS: from n/a through 1.8.12.
Title WordPress VikBooking Hotel Booking Engine & PMS plugin <= 1.8.12 - CSRF to Arbitrary File Deletion vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-01T17:57:59.550Z

Reserved: 2026-06-25T08:04:13.263Z

Link: CVE-2026-57723

cve-icon Vulnrichment

Updated: 2026-07-01T17:57:53.847Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-17T12:30:05Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)