What is CVE-2026-15346?
CVE-2026-15346 is a Reflected Cross-Site Scripting (XSS) vulnerability in the VikBooking Hotel Booking Engine & PMS plugin for WordPress via the 'category_id' parameter. All versions up to 1.8.13 are affected, allowing unauthenticated attackers to inject malicious scripts due to insufficient sanitization. Updating to the latest version is recommended.
Azərbaycanca: CVE-2026-15346 WordPress üçün VikBooking Hotel Booking Engine & PMS plaginində 'category_id' parametri vasitəsilə Reflected Cross-Site Scripting (XSS) zəifliyidir. 1.8.13 versiyasına qədər bütün versiyalar təsirlənir və autentifikasiya olunmamış hücumçulara zərərli skript yeritməyə imkan verir. Plaqini ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which plugin is affected by CVE-2026-15346 and which parameter is used for the attack?
This vulnerability affects the VikBooking Hotel Booking Engine & PMS plugin for WordPress, and the attack is carried out via the 'category_id' parameter.
What should be done to protect against CVE-2026-15346?
It is recommended to update the VikBooking plugin to the latest version.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.