CVE-2026-6818
- EPSS 0.24%
- Veröffentlicht 08.07.2026 11:30:31
- Zuletzt bearbeitet 08.07.2026 18:16:35
The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'special_requests' parameter in all versions up to, and including, 1.8.8 due to insufficient input sanitization and output escaping. T...
CVE-2024-11641
- EPSS 0.34%
- Veröffentlicht 26.01.2025 12:15:27
- Zuletzt bearbeitet 04.02.2025 19:53:14
The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7.2. This is due to missing or incorrect nonce validation on the 'save' function. This makes it possibl...
CVE-2023-25707
- EPSS 0.23%
- Veröffentlicht 23.05.2023 13:15:09
- Zuletzt bearbeitet 21.11.2024 07:49:58
Cross-Site Request Forgery (CSRF) vulnerability in E4J s.R.L. VikBooking Hotel Booking Engine & PMS plugin <= 1.5.12 versions.
CVE-2023-24396
- EPSS 0.39%
- Veröffentlicht 06.04.2023 14:15:08
- Zuletzt bearbeitet 21.11.2024 07:47:46
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in E4J s.R.L. VikBooking Hotel Booking Engine & PMS plugin <= 1.5.11 versions.