Reflected Cross-Site Scripting in VikBooking Hotel Booking Engine & PMS Plugin by WordPress
CVE-2026-15346
6.1MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 24 July 2026
What is CVE-2026-15346?
The VikBooking Hotel Booking Engine & PMS plugin for WordPress allows unauthenticated attackers to exploit reflected cross-site scripting vulnerabilities through insufficient input sanitization of the 'category_id' parameter. This flaw, present in all versions before 1.8.14, can enable attackers to inject arbitrary web scripts into user sessions, particularly if users are tricked into interacting with a manipulated link. The injection occurs in a hidden element, making it feasible for attacks on browsers supporting access keys.
Affected Version(s)
VikBooking Hotel Booking Engine & PMS 0 <= 1.8.13