Cross-site Scripting Vulnerability in VikBooking Hotel Booking Engine by e4jvikwp
CVE-2026-42683
7.1HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 1 June 2026
What is CVE-2026-42683?
The VikBooking Hotel Booking Engine & PMS by e4jvikwp contains a cross-site scripting (XSS) vulnerability, specifically an improper neutralization of input during web page generation. This flaw enables attackers to execute arbitrary scripts in the context of users' web browsers, potentially leading to data theft or unwanted actions on affected websites. The issue affects all versions from n/a to 1.8.8, highlighting the importance of applying security updates to mitigate risks associated with this vulnerability.
Affected Version(s)
VikBooking Hotel Booking Engine & PMS <= 1.8.8