Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Update the WordPress VikBooking Hotel Booking Engine & PMS plugin to the latest available version (at least 1.8.15).
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 09 Oct 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e4jvikwp VikBooking Hotel Booking Engine & PMS vikbooking allows Reflected XSS.This issue affects VikBooking Hotel Booking Engine & PMS: from n/a through 1.8.14. | |
| Title | WordPress VikBooking Hotel Booking Engine & PMS plugin <= 1.8.14 - Cross Site Scripting (XSS) vulnerability | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: Patchstack
Published:
Updated: 2026-10-09T10:00:19.352Z
Reserved: 2026-09-22T09:18:20.379Z
Link: CVE-2026-95591
No data.
Status : Received
Published: 2026-10-09T10:16:42.237
Modified: 2026-10-09T10:16:42.237
Link: CVE-2026-95591
No data.
OpenCVE Enrichment
Updated: 2026-10-09T12:00:07Z