{"api_version":"1","generated_at":"2026-09-18T07:44:27+00:00","cve":"CVE-2026-85127","urls":{"html":"https://cve.report/CVE-2026-85127","api":"https://cve.report/api/cve/CVE-2026-85127.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-85127","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-85127"},"summary":{"title":"VikBooking 1.8.8 - 1.8.14 - Unauthenticated Stored XSS via SVG Chat Attachment","description":"The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.8.15 does not restrict the type of files unauthenticated visitors may attach to its live chat, nor sanitize their contents, allowing them to store active content which is executed in the context of an administrator viewing the conversation.","state":"PUBLISHED","assigner":"WPScan","published_at":"2026-09-18 06:16:40","updated_at":"2026-09-18 06:16:40"},"problem_types":["CWE-79 Cross-Site Scripting (XSS)"],"metrics":[],"references":[{"url":"https://wpscan.com/vulnerability/4bca17fb-e9b4-4dc7-994f-08ce4aafadc7/","name":"https://wpscan.com/vulnerability/4bca17fb-e9b4-4dc7-994f-08ce4aafadc7/","refsource":"contact@wpscan.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-85127","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-85127","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Unknown","product":"VikBooking Hotel Booking Engine & PMS","version":"affected 1.8.8 1.8.15 semver","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"anhdung1329","lang":"en"},{"source":"CNA","value":"WPScan","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"VikBooking Hotel Booking Engine & PMS","vendor":"Unknown","versions":[{"lessThan":"1.8.15","status":"affected","version":"1.8.8","versionType":"semver"}]}],"credits":[{"lang":"en","type":"finder","value":"anhdung1329"},{"lang":"en","type":"coordinator","value":"WPScan"}],"descriptions":[{"lang":"en","value":"The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.8.15 does not restrict the type of files unauthenticated visitors may attach to its live chat, nor sanitize their contents, allowing them to store active content which is executed in the context of an administrator viewing the conversation."}],"problemTypes":[{"descriptions":[{"description":"CWE-79 Cross-Site Scripting (XSS)","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-09-18T06:00:13.511Z","orgId":"1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81","shortName":"WPScan"},"references":[{"tags":["exploit","vdb-entry","technical-description"],"url":"https://wpscan.com/vulnerability/4bca17fb-e9b4-4dc7-994f-08ce4aafadc7/"}],"source":{"discovery":"EXTERNAL"},"title":"VikBooking 1.8.8 - 1.8.14 - Unauthenticated Stored XSS via SVG Chat Attachment","x_generator":{"engine":"WPScan CVE Generator"}}},"cveMetadata":{"assignerOrgId":"1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81","assignerShortName":"WPScan","cveId":"CVE-2026-85127","datePublished":"2026-09-18T06:00:13.511Z","dateReserved":"2026-09-03T08:38:53.210Z","dateUpdated":"2026-09-18T06:00:13.511Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-18 06:16:40","lastModifiedDate":"2026-09-18 06:16:40","problem_types":["CWE-79 Cross-Site Scripting (XSS)"],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"85127","Ordinal":"1","Title":"VikBooking 1.8.8 - 1.8.14 - Unauthenticated Stored XSS via SVG C","CVE":"CVE-2026-85127","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"85127","Ordinal":"1","NoteData":"The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.8.15 does not restrict the type of files unauthenticated visitors may attach to its live chat, nor sanitize their contents, allowing them to store active content which is executed in the context of an administrator viewing the conversation.","Type":"Description","Title":"VikBooking 1.8.8 - 1.8.14 - Unauthenticated Stored XSS via SVG C"}]}}}