๐Ÿ” CVE Alert

CVE-2026-85127

UNKNOWN 0.0

VikBooking 1.8.8 - 1.8.14 - Unauthenticated Stored XSS via SVG Chat Attachment

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.8.15 does not restrict the type of files unauthenticated visitors may attach to its live chat, nor sanitize their contents, allowing them to store active content which is executed in the context of an administrator viewing the conversation.

Vendor unknown
Product vikbooking hotel booking engine & pms
Published Sep 18, 2026
Stay Ahead of the Next One

Get instant alerts for unknown vikbooking hotel booking engine & pms

Be the first to know when new unknown vulnerabilities affecting unknown vikbooking hotel booking engine & pms are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / VikBooking Hotel Booking Engine & PMS
1.8.8 < 1.8.15

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/4bca17fb-e9b4-4dc7-994f-08ce4aafadc7/

Credits

anhdung1329 WPScan