What is CVE-2026-15401?
This is a Stored Cross-Site Scripting (XSS) vulnerability in the VikBooking Hotel Booking Engine & PMS plugin for WordPress (versions up to 1.8.13). Due to insufficient input sanitization and output escaping on the 'vbfX' parameter, unauthenticated attackers can inject malicious scripts. Users are advised to update the plugin to the latest version immediately.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which WordPress plugin is affected by CVE-2026-15401?
The VikBooking Hotel Booking Engine & PMS plugin, versions up to 1.8.13, is affected by this vulnerability.
How can attackers exploit CVE-2026-15401?
Unauthenticated attackers can inject malicious scripts due to insufficient input sanitization on the 'vbfX' parameter.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.