Junglewise Threat Intelligence

CVE-2026-42683: e4jvikwp VikBooking Hotel Booking Engine DOM-based XSS

CVE-2026-42683 · Severity: high · CVSS 7.1 · Published 2026-06-01

Technologies: E4jvikwp VikBooking Hotel Booking Engine & PMS. Vendors: E4jvikwp.

Executive brief

VikBooking is a WordPress plugin used by hotels to manage room bookings and property management systems. A security flaw allows attackers to inject malicious scripts into the website, which could lead to unauthorized actions being performed in a user's browser, such as stealing session information or redirecting guests to fraudulent sites. This typically occurs when a victim clicks a specially crafted link provided by the attacker.

Technical details

A DOM-based Cross-Site Scripting (XSS) vulnerability exists in the VikBooking Hotel Booking Engine & PMS plugin due to improper neutralization of user-supplied input during web page generation. The flaw allows unauthenticated attackers to inject malicious scripts into the Document Object Model (DOM) environment. Exploitation requires a victim to interact with a malicious link or page (User Interaction required). Successful exploitation can lead to the execution of arbitrary JavaScript in the context of the victim's browser session, potentially allowing for session hijacking or unauthorized administrative actions if the victim is an authenticated user. The issue is resolved in version 1.8.9.

Affected products

  • e4jvikwp VikBooking Hotel Booking Engine & PMS up to 1.8.8

Timeline

  • 2026-04-20: other: Vulnerability reported by researcher
  • 2026-05-20: advisory: Patchstack advisory published
  • 2026-06-01: disclosed: CVE published to NVD dataset
  • 2026-05-20: patched: Version 1.8.9 released to address the issue

References

Related threats