CVE-2026-42737 HIGH

CVE-2026-42737: WordPress VikBooking Hotel Booking Engine & PMS plugin <= 1.8.9 - Arbitrary File Deletion vulnerability

Vendor E4Jvikwp
Product VikBooking Hotel Booking Engine & PMS
Weakness CWE-22 · Path traversal
Published May 27, 2026
Last update May 27, 2026

CVSS base score

8.6/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality None
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

What the vulnerability does

01Description

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in e4jvikwp VikBooking Hotel Booking Engine & PMS vikbooking allows Path Traversal.This issue affects VikBooking Hotel Booking Engine & PMS: from n/a through <= 1.8.9.

Explanation of Vulnerability in Simple Terms

02Summary

VikBooking Hotel Booking Engine & PMS versions 1.8.9 and earlier contain a path traversal vulnerability that allows unauthenticated attackers to disrupt site availability. An attacker can send specially crafted requests over the network to cause a denial of service. The vulnerability affects the entire application scope due to its network-accessible nature.

What an attacker can do

03Attacker Capabilities

Make the site unavailable or unresponsive by sending malicious requests.

Potential impact on your site

04Site Impact

Your booking engine may become unavailable to customers without warning or ability to prevent it.

Conditions required to exploit

05Prerequisites

Network access only; no authentication or user interaction required.

Key dates

06Disclosure timeline

May 27, 2026 CVE published
May 27, 2026 Record updated

Related vulnerabilities

08Related CVE