Description
The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.8.15 does not restrict the type of files unauthenticated visitors may attach to its live chat, nor sanitize their contents, allowing them to store active content which is executed in the context of an administrator viewing the conversation.
Published: 2026-09-18
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Stored XSS
Action: Patch Upgrade
AI Analysis

Impact

The vulnerability allows an unauthenticated visitor to upload malicious files, such as SVG attachments, to the chat feature of the VikBooking Hotel Booking Engine & PMS WordPress plugin. These files are not restricted by type and are not sanitized by the plugin, enabling the attacker to inject active script content. When an administrator accesses the stored chat conversation, the embedded script is executed in the admin browser context, which can lead to credential theft, defacement, or further compromise. The weakness corresponds to Cross‑Site Scripting (CWE‑79).

Affected Systems

The issue affects the VikBooking Hotel Booking Engine & PMS WordPress plugin versions from 1.8.8 through 1.8.14 inclusive. Users running any of these release numbers on a WordPress installation are vulnerable. The affected component is the live chat file‑upload functionality within the plugin.

Risk and Exploitability

The CVSS score of 8.8 classifies the flaw as high severity, but the EPSS score indicates a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack vector involves unauthenticated users uploading malicious files via the public chat interface, which are then stored and later rendered by an administrator, indicating a privilege escalation vector that can be leveraged without needing to first compromise a user account. Because the flaw requires only unauthenticated access and the attacker only needs to prompt an administrator to load the stored content, the risk is significant for sites that enable the chat feature for guest users.

Generated by OpenCVE AI on September 19, 2026 at 19:20 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the VikBooking plugin to version 1.8.15 or later to remove the vulnerability.
  • Configure the plugin or server to allow only safe file types (e.g., images) for chat attachments and strip disallowed content.
  • Disable or restrict the live chat feature for unauthenticated visitors until a permanent fix or workaround is applied.

Generated by OpenCVE AI on September 19, 2026 at 19:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
First Time appeared Vikwp
Vikwp vikbooking Hotel Booking Engine & Pms
Wordpress-extensions
Wordpress-extensions vikbooking
Vendors & Products Vikwp
Vikwp vikbooking Hotel Booking Engine & Pms
Wordpress-extensions
Wordpress-extensions vikbooking

Fri, 18 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Description The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.8.15 does not restrict the type of files unauthenticated visitors may attach to its live chat, nor sanitize their contents, allowing them to store active content which is executed in the context of an administrator viewing the conversation.
Title VikBooking 1.8.8 - 1.8.14 - Unauthenticated Stored XSS via SVG Chat Attachment
References

Subscriptions

Vikwp Vikbooking Hotel Booking Engine & Pms
Wordpress-extensions Vikbooking
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-18T11:11:25.467Z

Reserved: 2026-09-03T08:38:53.210Z

Link: CVE-2026-85127

cve-icon Vulnrichment

Updated: 2026-09-18T11:03:47.439Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T06:16:40.093

Modified: 2026-09-18T19:08:32.830

Link: CVE-2026-85127

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-29T13:21:58Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')