← Back

Vikbooking Hotel Booking Engine & Property Management System Plugin

vikbooking_hotel_booking_engine_&_property_management_system_plugin

Vendor: Vikwp • 2 CVEs

CVEs (2)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Vikwp
1Vikbooking Hotel Booking Engine & Property Management System Plugin
Nov 21, 2024
Apr 19, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Sensitive Information Exposure in E4J s.r.l. VikBooking Hotel Booking Engine & PMS plugin <= 1.5.3 on WordPress allows attackers to get the booking data by guessing / brute-forcing easy predictable booking IDs via search...Show more
Sensitive Information Exposure in E4J s.r.l. VikBooking Hotel Booking Engine & PMS plugin <= 1.5.3 on WordPress allows attackers to get the booking data by guessing / brute-forcing easy predictable booking IDs via search POST requests.Show less
1Vikwp
1Vikbooking Hotel Booking Engine & Property Management System Plugin
Nov 21, 2024
Apr 19, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Arbitrary File Upload leading to RCE in E4J s.r.l. VikBooking Hotel Booking Engine & PMS plugin <= 1.5.3 on WordPress allows attackers to upload and execute dangerous file types (e.g. PHP shell) via the signature upload...Show more
Arbitrary File Upload leading to RCE in E4J s.r.l. VikBooking Hotel Booking Engine & PMS plugin <= 1.5.3 on WordPress allows attackers to upload and execute dangerous file types (e.g. PHP shell) via the signature upload on the booking form.Show less