Impact
The vulnerability allows an unauthenticated visitor to upload malicious files, such as SVG attachments, to the chat feature of the VikBooking Hotel Booking Engine & PMS WordPress plugin. These files are not restricted by type and are not sanitized by the plugin, enabling the attacker to inject active script content. When an administrator accesses the stored chat conversation, the embedded script is executed in the admin browser context, which can lead to credential theft, defacement, or further compromise. The weakness corresponds to Cross‑Site Scripting (CWE‑79).
Affected Systems
The issue affects the VikBooking Hotel Booking Engine & PMS WordPress plugin versions from 1.8.8 through 1.8.14 inclusive. Users running any of these release numbers on a WordPress installation are vulnerable. The affected component is the live chat file‑upload functionality within the plugin.
Risk and Exploitability
The CVSS score of 8.8 classifies the flaw as high severity, but the EPSS score indicates a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack vector involves unauthenticated users uploading malicious files via the public chat interface, which are then stored and later rendered by an administrator, indicating a privilege escalation vector that can be leveraged without needing to first compromise a user account. Because the flaw requires only unauthenticated access and the attacker only needs to prompt an administrator to load the stored content, the risk is significant for sites that enable the chat feature for guest users.
OpenCVE Enrichment