Skip to main content

Vendor/product archive

vikwp / hotel_booking_engine_&_pms CVEs

Beta · best-effort

3 CVEs tagged to vikwp / hotel_booking_engine_&_pms0 Critical, 1 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2022-1409

Published May 16, 2022

The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.5.8 does not properly validate images, allowing high privilege users such as administrators to upload PHP files…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2022-1408

Published May 16, 2022

The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.5.8 does not escape various settings before outputting them in attributes, which could allow high privilege use…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-1407

Published May 16, 2022

The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.5.8 does not have CSRF check in place when adding a tracking campaign, and does not escape the campaign fields…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-3 of 3 CVEsPage 1 of 1