---
id: CVE-2026-85127
title: >-
  The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.8.15 does
  not restrict the type of files unauthenticated visitors may attach to its live
  chat, nor sanitize their contents, allowing them to store active content which
  i…
summary: >-
  The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.8.15 does
  not restrict the type of files unauthenticated visitors may attach to its live
  chat, nor sanitize their contents, allowing them to store active content which
  i…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'
cwe:
  - CWE-79
product: VikBooking Hotel Booking Engine & PMS
affected:
  - vikbooking_hotel_booking_engine_pms >= 1.8.8 < 1.8.15
published: '2026-09-18'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T19:08:32.830'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-85127'
references:
  - url: 'https://wpscan.com/vulnerability/4bca17fb-e9b4-4dc7-994f-08ce4aafadc7/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
epss: 0.0045
epssPercentile: 0.36405
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-18T11:04:27.532587Z'
ingestedAt: '2026-09-18T06:36:37.983Z'
---

## Overview

The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.8.15 does not restrict the type of files unauthenticated visitors may attach to its live chat, nor sanitize their contents, allowing them to store active content which is executed in the context of an administrator viewing the conversation.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
