PT-2025-21459 · WordPress · Vikbooking Hotel Booking Engine & Pms

Krugov Artyom

·

Published

2025-05-15

·

Updated

2025-06-10

·

CVE-2024-13616

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: VikBooking Hotel Booking Engine & PMS WordPress plugin versions prior to 1.7.2
Description: The issue concerns the VikBooking Hotel Booking Engine & PMS WordPress plugin, where certain settings are not properly sanitized and escaped. This could allow high-privilege users, such as administrators, to perform Stored Cross-Site Scripting attacks. This issue is notable even in setups where the unfiltered html capability is disallowed, such as in multisite configurations.
Recommendations: For versions prior to 1.7.2, update to version 1.7.2 or later to resolve the issue. As a temporary workaround, consider restricting administrative access to trusted users only until the update can be applied.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-13616

Affected Products

Vikbooking Hotel Booking Engine & Pms