Executive brief
The VikBooking Hotel Booking Engine & PMS plugin for WordPress, which manages hotel reservations and property management tasks, contains a security flaw. An attacker can inject malicious scripts into the 'special requests' field during a booking, which then run in the browser of any staff member or administrator who views that booking. This could lead to unauthorized access to the website's management dashboard or the theft of sensitive administrative session data.
Technical details
The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on the 'special_requests' parameter. An unauthenticated remote attacker can submit a booking request containing malicious JavaScript. When an administrative user views the booking details in the backend (e.g., via editorder or booking_details views), the script executes in their browser context. This can lead to session hijacking or unauthorized administrative actions. The issue is fixed in version 1.8.9.
Affected products
- e4jvikwp VikBooking Hotel Booking Engine & PMS up to, and including, 1.8.8
Timeline
- 2026-07-08: disclosed
- 2026-07-08: advisory
References
- https://plugins.trac.wordpress.org/browser/vikbooking/tags/1.8.9/admin/helpers/widgets/booking_details.php
- https://plugins.trac.wordpress.org/browser/vikbooking/tags/1.8.9/admin/views/editorder/tmpl/default.php
- https://plugins.trac.wordpress.org/browser/vikbooking/tags/1.8.9/admin/views/orders/tmpl/default.php
- https://www.wordfence.com/threat-intel/vulnerabilities/id/13a96e78-c83c-4ff1-a751-3dbaeb683d9d?source=cve