Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e4jvikwp VikBooking Hotel Booking Engine & PMS vikbooking allows Reflected XSS.This issue affects VikBooking Hotel Booking Engine & PMS: from n/a through 1.8.14.
Published: 2026-10-09
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: Reflected Cross‑Site Scripting (XSS)
Action: Immediate Patch
AI Analysis

Impact

This vulnerability arises from improper neutralization of user‑supplied input during page generation, allowing attackers to inject malicious scripts that execute within the victim’s browser. The impact is that an attacker can steal session cookies, deface content, or launch further attacks against users who view the affected page.

Affected Systems

WordPress sites running e4jvikwp VikBooking Hotel Booking Engine & PMS version 1.8.14 or earlier are affected. The specific product is the VikBooking plugin, and all releases before 1.8.15 contain the flaw.

Risk and Exploitability

The CVSS score is 7.1, indicating a high impact if exploited. No EPSS score is available, and the vulnerability is not yet listed in CISA KEV. The likely attack vector is reflected input via web forms that the plugin processes, which means an attacker can craft a URL or form payload to deliver the malicious script to any user viewing the page.

Generated by OpenCVE AI on October 9, 2026 at 11:47 UTC.

Remediation

Vendor Solution

Update the WordPress VikBooking Hotel Booking Engine & PMS plugin to the latest available version (at least 1.8.15).


OpenCVE Recommended Actions

  • Update the VikBooking plugin to version 1.8.15 or newer.
  • If an update cannot be applied immediately, restrict or sanitize all input handled by the plugin, ensuring that any user‑supplied data is properly escaped before rendering.
  • After remediation, run a site‑wide vulnerability scan to confirm that the XSS vectors have been removed.

Generated by OpenCVE AI on October 9, 2026 at 11:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 09 Oct 2026 10:15:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e4jvikwp VikBooking Hotel Booking Engine & PMS vikbooking allows Reflected XSS.This issue affects VikBooking Hotel Booking Engine & PMS: from n/a through 1.8.14.
Title WordPress VikBooking Hotel Booking Engine & PMS plugin <= 1.8.14 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-09T10:00:19.352Z

Reserved: 2026-09-22T09:18:20.379Z

Link: CVE-2026-95591

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-09T10:16:42.237

Modified: 2026-10-09T10:16:42.237

Link: CVE-2026-95591

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T12:00:07Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')