Vikwp develops a focused line of hotel and travel management solutions, including booking engines, property management systems, and car rental platforms that handle customer-facing reservations and administrative functions. Its vulnerability profile centers on web application input-handling and access-control weaknesses—cross-site scripting, cross-site request forgery, unrestricted file uploads, and information disclosure—that are characteristic of e-commerce and administrative interfaces managing sensitive guest and payment data. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Vikwp over time
Signals from CVEs in this vendor scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-27862CRITICAL Arbitrary File Upload leading to RCE in E4J s.r.l. VikBooking Hotel Booking Engine & PMS plugin <= 1.5.3 on WordPress allows attackers to upload and execute dangerous file types (e | Apr 19, 2022 | 9.8 | 31 | NO | NO |
CVE-2024-2441HIGH The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.6.8 allows direct access to menus, allowing an authenticated user with subscriber privileges or above, to bypass | May 14, 2024 | 8.1 | 26 | NO | NO |
CVE-2023-25707HIGH Cross-Site Request Forgery (CSRF) vulnerability in E4J s.R.L. VikBooking Hotel Booking Engine & PMS plugin <= 1.5.12 versions. | May 23, 2023 | 8.8 | 26 | NO | NO |
CVE-2024-11641HIGH The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7.2. This is due to missing or in | Jan 26, 2025 | 8.8 | 24 | NO | NO |
CVE-2023-32501HIGH Cross-Site Request Forgery (CSRF) vulnerability in E4J s.R.L. VikBooking Hotel Booking Engine & PMS plugin <= 1.6.1 versions. | Nov 9, 2023 | 8.8 | 24 | NO | NO |
CVE-2022-1409HIGH The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.5.8 does not properly validate images, allowing high privilege users such as administrators to upload PHP files | May 16, 2022 | 7.2 | 24 | NO | NO |
CVE-2022-27863MEDIUM Sensitive Information Exposure in E4J s.r.l. VikBooking Hotel Booking Engine & PMS plugin <= 1.5.3 on WordPress allows attackers to get the booking data by guessing / brute-forcing | Apr 19, 2022 | 5.3 | 20 | NO | NO |
CVE-2024-2749MEDIUM The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.6.8's access control mechanism fails to properly restrict access to its settings, permitting any users that can | May 14, 2024 | 5.9 | 18 | NO | NO |
CVE-2022-1528MEDIUM The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.5.9 does not escape the current URL before putting it back in a JavaScript context, leading to a Reflected Cross | May 30, 2022 | 6.1 | 18 | NO | NO |
CVE-2022-1407MEDIUM The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.5.8 does not have CSRF check in place when adding a tracking campaign, and does not escape the campaign fields w | May 16, 2022 | 6.5 | 18 | NO | NO |
Signals from CVEs in this vendor scope (14 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Vikwp.
Media articles that mention a CVE ID that affects a product developed by Vikwp — matched by CVE ID, not by vendor name.