PT-2025-1676 · WordPress · Vikbooking Hotel Booking Engine & Pms

Noah Stead

+1

·

Published

2025-01-26

·

Updated

2025-02-04

·

CVE-2024-11641

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions VikBooking Hotel Booking Engine & PMS plugin for WordPress versions up to, and including, 1.7.2
Description The issue is due to missing or incorrect nonce validation on the save function, making it possible for unauthenticated attackers to change plugin access privileges via a forged request. This can be achieved by tricking a site administrator into performing an action such as clicking on a link. Successful exploitation allows attackers with subscriber-level privileges and above to upload arbitrary files on the affected site's server, which may make remote code execution possible.
Recommendations For versions up to, and including, 1.7.2, update to a version that includes the fix for the nonce validation issue in the save function. As a temporary workaround, consider restricting access to the save function to minimize the risk of exploitation. Additionally, restrict privileges to the minimum required for each user to reduce the potential impact of the issue.

Fix

RCE

CSRF

Weakness Enumeration

Related Identifiers

CVE-2024-11641

Affected Products

Vikbooking Hotel Booking Engine & Pms