Junglewise Threat Intelligence

CVE-2026-12754: e4jvikwp VikBooking Hotel Booking Engine reflected XSS in layoutstyle

CVE-2026-12754 · Severity: medium · CVSS 6.1 · Published 2026-07-01

Technologies: E4jvikwp VikBooking Hotel Booking Engine & PMS. Vendors: E4jvikwp.

Executive brief

The VikBooking Hotel Booking Engine & PMS plugin for WordPress, which manages hotel reservations and property systems, is vulnerable to a security flaw that allows attackers to run malicious scripts in a user's browser. By tricking a user into clicking a specially crafted link, an attacker could potentially steal session information or perform actions on behalf of the user. This issue affects websites using the plugin's room list display feature.

Technical details

A Reflected Cross-Site Scripting (XSS) vulnerability exists in the VikBooking Hotel Booking Engine & PMS plugin for WordPress due to insufficient sanitization and escaping of the 'layoutstyle' parameter. The vulnerability is specifically located within the 'roomslist' view context, triggered when the [vikbooking view="roomslist"] shortcode is rendered. An unauthenticated attacker can exploit this by crafting a malicious URL containing a script payload and persuading a user to visit it. Successful exploitation allows the execution of arbitrary JavaScript in the context of the victim's browser session. The issue is addressed in version 1.8.13.

Affected products

  • e4jvikwp VikBooking Hotel Booking Engine & PMS up to, and including, 1.8.12

Timeline

  • 2026-07-01: advisory: NVD publication date
  • 2026-07-01: disclosed: Wordfence advisory published

References