Reflected Cross-Site Scripting in VikBooking Hotel Booking Engine & PMS Plugin by WordPress
CVE-2026-15346

6.1MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
24 July 2026

What is CVE-2026-15346?

The VikBooking Hotel Booking Engine & PMS plugin for WordPress allows unauthenticated attackers to exploit reflected cross-site scripting vulnerabilities through insufficient input sanitization of the 'category_id' parameter. This flaw, present in all versions before 1.8.14, can enable attackers to inject arbitrary web scripts into user sessions, particularly if users are tricked into interacting with a manipulated link. The injection occurs in a hidden element, making it feasible for attacks on browsers supporting access keys.

Affected Version(s)

VikBooking Hotel Booking Engine & PMS 0 <= 1.8.13

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Wordfence PRISM
.