cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forvikbooking vikbooking

Direction: descending
May 17, 2025

VikBooking Hotel Booking Engine & PMS # CVE-2024-13616

CVE, Research URL

CVE-2024-13616

Date
May 16, 2025
Research Description
The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.7.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
Affected versions
max 1.7.2.
Status
vulnerable
Feb 21, 2025

VikBooking Hotel Booking Engine & PMS # CVE-2025-22670

CVE, Research URL

CVE-2025-22670

Date
Mar 27, 2025
Research Description
Missing Authorization vulnerability in e4jvikwp VikBooking Hotel Booking Engine & PMS allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects VikBooking Hotel Booking Engine & PMS: from n/a through 1.7.2.
Affected versions
max 1.7.3.
Status
vulnerable
Jan 28, 2025

VikBooking Hotel Booking Engine & PMS # CVE-2024-11641

CVE, Research URL

CVE-2024-11641

Date
Jan 26, 2025
Research Description
The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7.2. This is due to missing or incorrect nonce validation on the 'save' function. This makes it possible for unauthenticated attackers to change plugin access privileges via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. Successful exploitation allows attackers with subscriber-level privileges and above to upload arbitrary files on the affected site's server which may make remote code execution possible.
Affected versions
max 1.7.3.
Status
vulnerable
Jun 07, 2024

VikBooking Hotel Booking Engine & PMS # CVE-2022-1408

CVE, Research URL

CVE-2022-1408

Date
May 16, 2022
Research Description
The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.5.8 does not escape various settings before outputting them in attributes, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed
Affected versions
max 1.5.8.
Status
vulnerable

VikBooking Hotel Booking Engine & PMS # CVE-2023-24396

CVE, Research URL

CVE-2023-24396

Date
Apr 06, 2023
Research Description
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in E4J s.R.L. VikBooking Hotel Booking Engine & PMS plugin <= 1.5.11 versions.
Affected versions
max 1.6.0.
Status
vulnerable

VikBooking Hotel Booking Engine &amp; PMS # CVE-2023-25707

CVE, Research URL

CVE-2023-25707

Date
May 23, 2023
Research Description
Cross-Site Request Forgery (CSRF) vulnerability in E4J s.R.L. VikBooking Hotel Booking Engine & PMS plugin <= 1.5.12 versions.
Affected versions
max 1.6.0.
Status
vulnerable

VikBooking Hotel Booking Engine &amp; PMS # CVE-2022-27862

CVE, Research URL

CVE-2022-27862

Date
Apr 20, 2022
Research Description
Arbitrary File Upload leading to RCE in E4J s.r.l. VikBooking Hotel Booking Engine & PMS plugin <= 1.5.3 on WordPress allows attackers to upload and execute dangerous file types (e.g. PHP shell) via the signature upload on the booking form.
Affected versions
max 1.5.9.
Status
vulnerable

VikBooking Hotel Booking Engine &amp; PMS # CVE-2022-1407

CVE, Research URL

CVE-2022-1407

Date
May 16, 2022
Research Description
The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.5.8 does not have CSRF check in place when adding a tracking campaign, and does not escape the campaign fields when outputting them In attributes. As a result, attackers could make a logged in admin add tracking campaign with XSS payloads in them via a CSRF attack
Affected versions
max 1.5.8.
Status
vulnerable

VikBooking Hotel Booking Engine &amp; PMS # CVE-2024-2441

CVE, Research URL

CVE-2024-2441

Date
May 14, 2024
Research Description
The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.6.8 allows direct access to menus, allowing an authenticated user with subscriber privileges or above, to bypass authorization and access settings of the VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.6.8's they shouldn't be allowed to.
Affected versions
max 1.6.8.
Status
vulnerable

VikBooking Hotel Booking Engine &amp; PMS # CVE-2024-2749

CVE, Research URL

CVE-2024-2749

Date
May 14, 2024
Research Description
The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.6.8's access control mechanism fails to properly restrict access to its settings, permitting any users that can access a menu to manipulate requests and perform unauthorized actions such as editing, renaming or deleting (categories for example) despite initial settings prohibiting such access. This vulnerability resembles broken access control, enabling unauthorized users to modify critical VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.6.8 configurations.
Affected versions
max 1.6.8.
Status
vulnerable

VikBooking Hotel Booking Engine &amp; PMS # CVE-2022-1528

CVE, Research URL

CVE-2022-1528

Date
May 30, 2022
Research Description
The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.5.9 does not escape the current URL before putting it back in a JavaScript context, leading to a Reflected Cross-Site Scripting
Affected versions
max 1.5.9.
Status
vulnerable

VikBooking Hotel Booking Engine &amp; PMS # CVE-2022-1409

CVE, Research URL

CVE-2022-1409

Date
May 16, 2022
Research Description
The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.5.8 does not properly validate images, allowing high privilege users such as administrators to upload PHP files disguised as images and containing malicious PHP code
Affected versions
max 1.5.8.
Status
vulnerable

VikBooking Hotel Booking Engine &amp; PMS # CVE-2022-27863

CVE, Research URL

CVE-2022-27863

Date
Apr 20, 2022
Research Description
Sensitive Information Exposure in E4J s.r.l. VikBooking Hotel Booking Engine & PMS plugin <= 1.5.3 on WordPress allows attackers to get the booking data by guessing / brute-forcing easy predictable booking IDs via search POST requests.
Affected versions
max 1.5.9.
Status
vulnerable

VikBooking Hotel Booking Engine &amp; PMS # CVE-2023-32501

CVE, Research URL

CVE-2023-32501

Date
Nov 10, 2023
Research Description
Cross-Site Request Forgery (CSRF) vulnerability in E4J s.R.L. VikBooking Hotel Booking Engine & PMS plugin <= 1.6.1 versions.
Affected versions
max 1.6.2.
Status
vulnerable

VikBooking Hotel Booking Engine &amp; PMS # CVE-2024-32563

CVE, Research URL

CVE-2024-32563

Date
Apr 18, 2024
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VikBooking Hotel Booking Engine & PMS allows Reflected XSS.This issue affects VikBooking Hotel Booking Engine & PMS: from n/a through 1.6.7.
Affected versions
max 1.6.8.
Status
vulnerable