Impact
This vulnerability arises from improper neutralization of user‑supplied input during page generation, allowing attackers to inject malicious scripts that execute within the victim’s browser. The impact is that an attacker can steal session cookies, deface content, or launch further attacks against users who view the affected page.
Affected Systems
WordPress sites running e4jvikwp VikBooking Hotel Booking Engine & PMS version 1.8.14 or earlier are affected. The specific product is the VikBooking plugin, and all releases before 1.8.15 contain the flaw.
Risk and Exploitability
The CVSS score is 7.1, indicating a high impact if exploited. No EPSS score is available, and the vulnerability is not yet listed in CISA KEV. The likely attack vector is reflected input via web forms that the plugin processes, which means an attacker can craft a URL or form payload to deliver the malicious script to any user viewing the page.
OpenCVE Enrichment