Executive brief
VikBooking is a WordPress plugin used by hotels to manage room bookings and property management systems. A security flaw in this plugin allows an attacker to delete critical files from the website's server without needing to log in. This can lead to a complete service outage, website defacement, or the removal of essential security configurations, potentially breaking the site's functionality entirely.
Technical details
A path traversal vulnerability (CWE-22) exists in the VikBooking Hotel Booking Engine & PMS plugin for WordPress through version 1.8.9. The flaw allows an unauthenticated remote attacker to manipulate file paths to target files outside of the intended directory. By exploiting this, an attacker can trigger arbitrary file deletion on the server. According to the CVSS vector, the attack has a high impact on availability (A:H) and can affect components beyond the initial security scope (S:C). The issue is resolved in version 1.8.10.
Affected products
- e4jvikwp VikBooking Hotel Booking Engine & PMS <= 1.8.9
Timeline
- 2026-04-27: other: Reported by researcher dodoh4t
- 2026-05-27: disclosed: Vulnerability published by Patchstack
- 2026-05-27: patched: Fixed in version 1.8.10