Vikwp
vikwp
14 CVEs • 5 products
Products (5)
Click to collapseToggle
Products (5)
Click to collapse
CVEs (14)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Vikwp 1Vikbooking Hotel Booking Engine & Pms Jun 10, 2025 May 15, 2025 N/A· v4 4.8 MEDIUM· v3 N/A· v2 The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.7.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attac...Show more |
1Vikwp 1Vikbooking Hotel Booking Engine & Pms Feb 4, 2025 Jan 26, 2025 N/A· v4 8.8 HIGH· v3 N/A· v2 The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7.2. This is due to missing or incorrect nonce validation on the 'save' f...Show more |
1Vikwp 1Vikbooking Hotel Booking Engine & Pms May 5, 2025 May 14, 2024 N/A· v4 5.9 MEDIUM· v3 N/A· v2 The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.6.8's access control mechanism fails to properly restrict access to its settings, permitting any users that can access a menu to manipulate requests and...Show more |
1Vikwp 1Vikbooking Hotel Booking Engine & Pms May 5, 2025 May 14, 2024 N/A· v4 8.1 HIGH· v3 N/A· v2 The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.6.8 allows direct access to menus, allowing an authenticated user with subscriber privileges or above, to bypass authorization and access settings of th...Show more |
1Vikwp 1Vikbooking Hotel Booking Engine & Pms Apr 28, 2026 Nov 9, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Cross-Site Request Forgery (CSRF) vulnerability in E4J s.R.L. VikBooking Hotel Booking Engine & PMS plugin <= 1.6.1 versions. |
1Vikwp 1Vikbooking Hotel Booking Engine & Pms Nov 21, 2024 May 23, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Cross-Site Request Forgery (CSRF) vulnerability in E4J s.R.L. VikBooking Hotel Booking Engine & PMS plugin <= 1.5.12 versions. |
1Vikwp 1Vikbooking Hotel Booking Engine & Pms Nov 21, 2024 Apr 6, 2023 N/A· v4 4.8 MEDIUM· v3 N/A· v2 Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in E4J s.R.L. VikBooking Hotel Booking Engine & PMS plugin <= 1.5.11 versions. |
The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.5.9 does not escape the current URL before putting it back in a JavaScript context, leading to a Reflected Cross-Site Scripting |
1Vikwp 1Hotel Booking Engine & Pms Nov 21, 2024 May 16, 2022 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.5.8 does not properly validate images, allowing high privilege users such as administrators to upload PHP files disguised as images and containing malic...Show more |
1Vikwp 1Hotel Booking Engine & Pms Nov 21, 2024 May 16, 2022 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.5.8 does not escape various settings before outputting them in attributes, which could allow high privilege users such as admin to perform Cross-Site Sc...Show more |
1Vikwp 1Hotel Booking Engine & Pms Nov 21, 2024 May 16, 2022 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.5.8 does not have CSRF check in place when adding a tracking campaign, and does not escape the campaign fields when outputting them In attributes. As a...Show more |
1Vikwp 1Vikbooking Hotel Booking Engine & Property Management System Plugin Nov 21, 2024 Apr 19, 2022 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Sensitive Information Exposure in E4J s.r.l. VikBooking Hotel Booking Engine & PMS plugin <= 1.5.3 on WordPress allows attackers to get the booking data by guessing / brute-forcing easy predictable booking IDs via search...Show more |
1Vikwp 1Vikbooking Hotel Booking Engine & Property Management System Plugin Nov 21, 2024 Apr 19, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Arbitrary File Upload leading to RCE in E4J s.r.l. VikBooking Hotel Booking Engine & PMS plugin <= 1.5.3 on WordPress allows attackers to upload and execute dangerous file types (e.g. PHP shell) via the signature upload...Show more |
1Vikwp 1Car Rental Management System Nov 21, 2024 Aug 16, 2021 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 The VikRentCar Car Rental Management System WordPress plugin before 1.1.10 does not sanitise the 'Text Next to Icon' field when adding or editing a Characteristic, allowing high privilege users such as admin to use XSS p...Show more |