Junglewise Threat Intelligence

CVE-2026-42762: e4jvikwp VikBooking Hotel Booking Engine DOM XSS

CVE-2026-42762 · Severity: high · CVSS 7.1 · Published 2026-05-27

Technologies: E4jvikwp VikBooking Hotel Booking Engine & PMS. Vendors: E4jvikwp.

Executive brief

VikBooking is a popular WordPress plugin used by hotels and property managers to handle online reservations and room management. A security vulnerability in this plugin could allow an attacker to execute malicious scripts in the browser of a legitimate user, such as a site administrator or a customer. This could lead to unauthorized access to sensitive booking data, session hijacking, or the defacement of the website.

Technical details

A DOM-based Cross-Site Scripting (XSS) vulnerability exists in the VikBooking Hotel Booking Engine & PMS plugin (versions up to and including 1.8.9). The flaw stems from improper neutralization of user-supplied input during web page generation, specifically within the Document Object Model (DOM) environment. An unauthenticated remote attacker can exploit this by tricking a user into clicking a specially crafted link. Successful exploitation allows the attacker to execute arbitrary JavaScript in the context of the victim's browser session, potentially leading to credential theft or unauthorized administrative actions.

Affected products

  • e4jvikwp VikBooking Hotel Booking Engine & PMS <= 1.8.9

Timeline

  • 2026-05-27: disclosed
  • 2026-05-27: advisory

References

Related threats