Executive brief
A security vulnerability exists in the VikBooking Hotel Booking Engine & PMS plugin for WordPress, which is used to manage hotel reservations and property management tasks. An attacker could trick an administrator into clicking a malicious link, which would then allow the attacker to delete important files from the website's server. This could lead to significant service disruptions, loss of website functionality, or a complete site crash.
Technical details
A Cross-Site Request Forgery (CSRF) vulnerability exists in the e4jvikwp VikBooking Hotel Booking Engine & PMS plugin for WordPress (versions up to 1.8.12). The flaw stems from a lack of proper nonce validation, which, when combined with a path traversal weakness, allows an unauthenticated attacker to trick a logged-in administrator into performing unintended actions. Specifically, an attacker can leverage this to delete arbitrary files on the server by providing manipulated file paths. Successful exploitation requires the victim to interact with a malicious link or form. The issue is resolved in version 1.8.13.
Affected products
- e4jvikwp VikBooking Hotel Booking Engine & PMS n/a through 1.8.12
Timeline
- 2026-06-27: disclosed: Reported by VDsec
- 2026-07-01: advisory: Published by Patchstack and NVD
- 2026-07-01: patched: Version 1.8.13 released to address the issue