Impact
The vulnerability is a stored cross-site scripting flaw caused by insufficient sanitization and escaping of the 'attachments[name]' parameter in the VikBooking chat functionality. Unauthenticated attackers can inject arbitrary JavaScript that is persisted and later displayed to any user who loads a page containing the injected content. This flaw does not provide direct remote code execution on the server, but the injected script runs in the context of the victim’s browser and can be used to steal credentials, deface content or redirect users.
Affected Systems
WordPress sites using the VikBooking Hotel Booking Engine & PMS plugin, versions 1.8.15 and earlier. The flaw resides in the chat attachment handling code and affects every installation of these plugin versions that remains unpatched.
Risk and Exploitability
The vulnerability carries a CVSS score of 7.2, indicating a moderate to high severity. EPSS information is not available, and the issue is not currently listed in the CISA KEV catalog. Because the flaw is exploitable by unauthenticated users through normal web traffic, any public site using a vulnerable version exposes all visitors to the risk of script injection. Attack execution requires only sending a crafted request to the chat endpoint containing a malicious 'attachments[name]' value; once stored, any user viewing the affected page will execute the script. The modest CVSS score reflects the client‑side impact, but the ease of exploitation and broad impact to site visitors make it a significant concern.
OpenCVE Enrichment