CVE-2026-85127: CWE-79 Cross-Site Scripting (XSS) in VikBooking Hotel Booking Engine & PMS
The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.8.15 does not restrict the type of files unauthenticated visitors may attach to its live chat, nor sanitize their contents, allowing them to store active content which is executed in the context of an administrator viewing the conversation.
AI Analysis
Technical Summary
The VikBooking Hotel Booking Engine & PMS WordPress plugin before version 1.8.15 does not properly restrict file types or sanitize contents attached by unauthenticated users to its live chat. This allows storage and execution of active content (cross-site scripting) when an administrator views the conversation, potentially compromising the administrator's session or actions.
Potential Impact
An attacker can exploit this vulnerability to execute arbitrary scripts in the context of an administrator's browser session when viewing live chat messages. This could lead to session hijacking, unauthorized actions, or other impacts typical of XSS vulnerabilities. No known exploits in the wild have been reported.
Mitigation Recommendations
Upgrade the VikBooking Hotel Booking Engine & PMS plugin to version 1.8.15 or later, where this vulnerability is fixed. Until then, restrict access to the live chat feature or monitor for suspicious file attachments. Patch status is not explicitly confirmed in the provided data, so verify with the vendor for official fixes.
CVE-2026-85127: CWE-79 Cross-Site Scripting (XSS) in VikBooking Hotel Booking Engine & PMS
Description
The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.8.15 does not restrict the type of files unauthenticated visitors may attach to its live chat, nor sanitize their contents, allowing them to store active content which is executed in the context of an administrator viewing the conversation.
CVSS v3.1
Score 8.8high
Affected software
VikBooking Hotel Booking Engine & PMS
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The VikBooking Hotel Booking Engine & PMS WordPress plugin before version 1.8.15 does not properly restrict file types or sanitize contents attached by unauthenticated users to its live chat. This allows storage and execution of active content (cross-site scripting) when an administrator views the conversation, potentially compromising the administrator's session or actions.
Potential Impact
An attacker can exploit this vulnerability to execute arbitrary scripts in the context of an administrator's browser session when viewing live chat messages. This could lead to session hijacking, unauthorized actions, or other impacts typical of XSS vulnerabilities. No known exploits in the wild have been reported.
Mitigation Recommendations
Upgrade the VikBooking Hotel Booking Engine & PMS plugin to version 1.8.15 or later, where this vulnerability is fixed. Until then, restrict access to the live chat feature or monitor for suspicious file attachments. Patch status is not explicitly confirmed in the provided data, so verify with the vendor for official fixes.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- WPScan
- Date Reserved
- 2026-09-03T08:38:53.210Z
- State
- PUBLISHED
Threat ID: 6aacd5a155bf5e2cf5955f1b
Added to database: 09/18/2026, 06:09:37 UTC
Last enriched: 09/18/2026, 06:17:38 UTC
Last updated: 09/19/2026, 01:23:12 UTC
Views: 8
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.