VikBooking Hotel Booking Engine & PMS

Explore VikBooking Hotel Booking Engine & PMS vulnerabilities across all versions. Currently tracking 35 known vulnerabilities, including severity, impact, and patch status.

01234567891010.04.2018Today18.04.20225.3VikBooking Hotel Booking Engine & PMS <= 1.5.3 - Sensitive Information Exposure CVSS 5.3 · 18.04.20229.8VikBooking Hotel Booking Engine & PMS <= 1.5.3 - Arbitrary File Upload CVSS 9.8 · 18.04.202221.04.20225.5VikBooking Hotel Booking Engine & PMS <= 1.5.8 - Arbitrary File Upload CVSS 5.5 · 21.04.20228.8VikBooking Hotel Booking Engine & PMS <= 1.5.7 - Cross-Site Request Forgery to Stored Cross-Site Scripting CVSS 8.8 · 21.04.20225.5VikBooking Hotel Booking Engine & PMS <= 1.5.7 - Admin+ Stored Cross-Site Scripting CVSS 5.5 · 21.04.202203.05.20226.1VikBooking <= 1.5.8 - Reflected Cross-Site Scripting CVSS 6.1 · 03.05.202227.01.20234.4VikBooking Hotel Booking Engine & PMS <= 1.5.11 - Authenticated (Admin+) Stored Cross-Site Scripting CVSS 4.4 · 27.01.202315.02.20234.3VikBooking Hotel Booking Engine & PMS <= 1.5.12 - Cross-Site Request Forgery in exec_admin_widget function CVSS 4.3 · 15.02.20234.3VikBooking Hotel Booking Engine & PMS <= 1.5.12 - Cross-Site Request Forgery in widgets_watch_data function CVSS 4.3 · 15.02.20235.4VikBooking Hotel Booking Engine & PMS <= 1.5.12 - Cross-Site Request Forgery in savetranslation function CVSS 5.4 · 15.02.20235.4VikBooking Hotel Booking Engine & PMS <= 1.5.12 - Cross-Site Request Forgery in savetranslationstay function CVSS 5.4 · 15.02.20235.3VikBooking Hotel Booking Engine & PMS <= 1.5.12 - Cross-Site Request Forgery in save_admin_widgets function CVSS 5.3 · 15.02.20234.3VikBooking Hotel Booking Engine & PMS <= 1.5.12 - Cross-Site Request Forgery in exec_multitask_widgets function CVSS 4.3 · 15.02.20234.3VikBooking Hotel Booking Engine & PMS <= 1.6.1 - Cross-Site Request Forgery in listenTosFieldSavingTask function CVSS 4.3 · 15.02.20234.3VikBooking Hotel Booking Engine & PMS <= 1.5.12 - Cross-Site Request Forgery in admin_widgets_welcome function CVSS 4.3 · 15.02.20235.4VikBooking Hotel Booking Engine & PMS <= 1.5.12 - Cross-Site Request Forgery in savetmplfile function CVSS 5.4 · 15.02.20235.4VikBooking Hotel Booking Engine & PMS <= 1.5.12 - Cross-Site Request Forgery in saveconfig function CVSS 5.4 · 15.02.20234.3VikBooking Hotel Booking Engine & PMS <= 1.6.1 - Cross-Site Request Forgery in multiple functions in admin/controller.php CVSS 4.3 · 15.02.202316.04.20246.1VikBooking Hotel Booking Engine & PMS <= 1.6.7 - Reflected Cross-Site Scripting CVSS 6.1 · 16.04.202419.04.20244.3VikBooking Hotel Booking Engine & PMS <= 1.6.7 - Insecure Direct Object Reference to Menu Access CVSS 4.3 · 19.04.20245.4VikBooking Hotel Booking Engine & PMS <= 1.6.7 - Missing Authorization CVSS 5.4 · 19.04.202425.01.20258.8VikBooking Hotel Booking Engine & PMS <= 1.7.2 - Cross-Site Request Forgery to Authenticated (Subscriber+) Arbitrary File Upload CVSS 8.8 · 25.01.202503.02.20254.3VikBooking Hotel Booking Engine & PMS <= 1.7.2 - Cross-Site Request Forgery to Settings Update CVSS 4.3 · 03.02.202503.03.20254.4VikBooking Hotel Booking Engine & PMS <= 1.7.1 - Authenticated (Admin+) Stored Cross-Site Scripting CVSS 4.4 · 03.03.202521.10.20255.3VikBooking Hotel Booking Engine & PMS <= 1.8.2 - Missing Authorization CVSS 5.3 · 21.10.202507.11.20257.5VikBooking Hotel Booking Engine & PMS <= 1.8.2 - Unauthenticated Information Exposure CVSS 7.5 · 07.11.202520.05.20267.2VikBooking Hotel Booking Engine & PMS <= 1.8.8 - Unauthenticated Stored Cross-Site Scripting CVSS 7.2 · 20.05.202627.05.20269.1VikBooking Hotel Booking Engine & PMS <= 1.8.10 - Unauthenticated Arbitrary File Deletion CVSS 9.1 · 27.05.202601.06.20267.2VikBooking Hotel Booking Engine & PMS <= 1.8.9 - Unauthenticated Stored Cross-Site Scripting CVSS 7.2 · 01.06.202630.06.20266.1VikBooking Hotel Booking Engine & PMS <= 1.8.12 - Reflected Cross-Site Scripting via 'layoutstyle' Parameter CVSS 6.1 · 30.06.202601.07.20264.3VikBooking Hotel Booking Engine & PMS <= 1.8.12 - Cross-Site Request Forgery CVSS 4.3 · 01.07.202607.07.20267.2VikBooking Hotel Booking Engine & PMS <= 1.8.8 - Unauthenticated Stored Cross-Site Scripting via 'special_requests' Parameter CVSS 7.2 · 07.07.20267.2VikBooking Hotel Booking Engine & PMS <= 1.8.8 - Unauthenticated Stored Cross-Site Scripting via Booking Form Email Field CVSS 7.2 · 07.07.202623.07.20266.1VikBooking Hotel Booking Engine & PMS <= 1.8.13 - Reflected Cross-Site Scripting via 'category_id' Parameter CVSS 6.1 · 23.07.20267.2VikBooking Hotel Booking Engine & PMS <= 1.8.13 - Unauthenticated Stored Cross-Site Scripting via Custom Field 'vbfX' Parameter CVSS 7.2 · 23.07.2026

Strategic Overview

Avg CVSSMedium
5.9/ 10
Patch Coverage100%
Open

0

Fixed

35

Get automatic notifications for all VikBooking Hotel Booking Engine & PMS vulnerabilities before they are exploited.

Vulnerability Records

35 records
2026-07-23 20:31CVE-2026-15401
7.2
High
Wordfence PRISMYes
2026-07-23 19:03CVE-2026-15346
6.1
Medium
Wordfence PRISMYes
2026-07-07 23:40CVE-2026-6820
7.2
High
Naoya Takahashi (nakko)Yes
2026-07-07 23:14CVE-2026-6818
7.2
High
Azril Fathoni (kiseki)Yes
2026-07-01 00:00CVE-2026-57723
4.3
Medium
VDsecYes
2026-06-30 20:07CVE-2026-12754
6.1
Medium
Wordfence PRISMYes
2026-06-01 00:00CVE-2026-42762
7.2
High
anhcd05Yes
2026-05-27 00:00CVE-2026-42737
9.1
Critical
dodoh4tYes
2026-05-20 00:00CVE-2026-42683
7.2
High
Evan NRYes
2025-11-07 00:00CVE-2025-49918
7.5
High
darooYes
Showing 1–10 of 35 reports
VikBooking Hotel Booking Engine &amp; PMS banner
Latestv1.8.14

VikBooking Hotel Booking Engine &amp; PMS

e4jvikwp

Author

e4jvikwp

4.8(60)
96/100
Last Updated
2026-07-16 (13d ago)
Active Installs
8,000+
Downloads
267,346
Requires WP
4.7+
Requires PHP
7.4.0+
Tested up to
WP 7.0.2
Created
2018-04-10 (8y ago)

Vik Booking for WordPress The famous Booking Engine and PMS online software for accommodations is now available also for WordPress as a native Plugin! If you are looking for a reliable reservation system for a Hotel, B&B, Villa, Apartments, Hostel or any similar accommodation, then you have found the right plugin. In fact, Vik Booking is a PCI-DSS and OpenTravel compliant hotel & vacation rental Booking Engine used by thousands of properties every day. This is the free version of the plugin, but you can upgrade to the Pro version at any time from your wp-admin section. Experience the power of a true and internal Booking Engine that competes with the best ones of the world! The Pro version is compatible with Vik Channel Manager, the first and only native Channel Manager for WordPress, listed as a Premier Partner of Booking.com since 2018 among the top 20 systems worldwide. Full API connections available with the most famous OTAs such as Airbnb, Expedia and Google Hotel for their new Free Booking Links! Beware of “fake” Channel Manager plugins that only offer unreliable iCal synchronizations with no private access to the OTA’s APIs. Vik Booking was born in 2010 for a different web-software (CMS) than WordPress, and that’s how it became famous. The same powerful framework is now (since 2018) at the service of all webmasters, designers and web-agencies that work with WordPress. It’s definitely the hotel reservation plugin that you, or your client, were looking for. Visit VikWP.com for more details. Interested in our full solution inclusive of the Channel Manager? Visit also E4jConnect. Some of the unique features Custom Rate Plans (Refundable, Flexible, Non Refundable rates). Rooms, Room Types, Listings and Sub-Units management functions. Availability & Pricing Calendars + Occupancy Overview. Bookings Management made right. Feature-rich back-end section for your PMS. Front-end customizable and self-hosted booking process. 12 different Views for the front-end (12 types of Shortcode for your pages) Compliant with any Pricing Model: Occupancy, Nightly, LOS, OBP etc.. Housekeeping features with Tableaux, festivities and room-day notes. Permissions/ACL Management functions for the various WP Users Roles. Multi-language support with built-in translation functions. Channel Manager compatible. We are a certified Channel Manager provider (E4jConnect). Google Hotel Ads certified for Free Booking Links. Driver-based pre-check-in system for guests data collection. Some of Pro version features Seasonal Rates and Rates Calendar with 1-click modification. Booking Restrictions: Min, Max LOS, CTA/CTD, forced Arrival/Departure week days. Custom Payment Gateways (over 60 available on VikWP.com). SMS Gateways for automated notifications. Custom Cron Jobs scheduling for automated tasks (reminders, invoices). Customers Management functions, sales channels and commissions. Graphs and Statistics. Custom Options, Extra Services, Extra Fees. Add, Remove or Switch rooms from existing bookings. PMS Reports with extendable framework (built-in services for various countries). Electronic invoices extendable framework compliant with Italy (Agenzia delle Entrate), Greece (myDATA ΑΑΔΕ) etc.. Guest registration functions and reporting: check-in, check-out, no-show. WhatsApp Business messaging integration with AI support (Channel Manager required). Our award winning solution of Booking Engine + PMS and Channel Manager is all you need on your WordPress website. Interested in, curious about the Pro version? You should take a look with your own eyes at the demo website to see what you can do with Vik Booking. Do not stop at the front-end though, make sure to visit the wp-admin section too. Front-end Demo Website Admin Demo Website

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C