Junglewise Threat Intelligence

CVE-2026-15401: VikBooking Hotel Booking Engine & PMS Stored XSS in vbfX parameter

CVE-2026-15401 · Severity: high · CVSS 7.2 · Published 2026-07-24

Technologies: E4jvikwp VikBooking Hotel Booking Engine & PMS. Vendors: E4jvikwp.

Executive brief

VikBooking is a WordPress plugin used by hotels to manage room bookings and property management tasks. A security flaw allows unauthorized individuals to inject malicious scripts into the booking system, which could lead to the theft of customer data or administrative session hijacking when staff view booking details. This vulnerability is particularly serious because it requires no login or special permissions to exploit.

Technical details

The VikBooking Hotel Booking Engine & PMS plugin for WordPress contains a Stored Cross-Site Scripting (XSS) vulnerability due to insufficient input sanitization and output escaping on the 'vbfX' parameter. The root cause is located in the public-facing 'saveorder' task, which fails to enforce authentication or capability checks. An unauthenticated remote attacker can submit a malicious payload via a crafted request to the booking engine. This payload is stored in the database and executed in the context of any user (including administrators) who views the compromised booking record in the management interface. The vulnerability is addressed in versions following 1.8.13.

Affected products

  • e4jvikwp VikBooking Hotel Booking Engine & PMS up to, and including, 1.8.13

Timeline

  • 2026-07-24: disclosed
  • 2026-07-24: advisory

References