Back

HIGH

WordPress VikBooking Hotel Booking Engine & PMS plugin <= 1.8.12 - CSRF to Arbitrary File Deletion vulnerability

Published Jul 1, 2026

Description

Cross-Site Request Forgery (CSRF) vulnerability in e4jvikwp VikBooking Hotel Booking Engine & PMS allows Path Traversal.

This issue affects VikBooking Hotel Booking Engine & PMS: from n/a through 1.8.12.

Affected products

Remediation

Vendor solution

Update the WordPress VikBooking Hotel Booking Engine & PMS Plugin to the latest available version (at least 1.8.13).

Metrics

Weaknesses (1)

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Patchstack
Published Jul 1, 2026
Updated Jul 1, 2026
Reserved Jun 25, 2026
CISA Vulnrichment
Updated Jul 1, 2026
NVD
Status Deferred
Modified Jul 1, 2026
Red Hat
Severity n/a
Public date n/a