VYPR
Medium severity5.3NVD Advisory· Published Nov 6, 2025· Updated Apr 27, 2026

CVE-2025-5803

CVE-2025-5803

Description

Missing Authorization vulnerability in e4jvikwp VikBooking Hotel Booking Engine & PMS vikbooking.This issue affects VikBooking Hotel Booking Engine & PMS: from n/a through <= 1.8.2.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

VikBooking Hotel Booking Engine & PMS plugin up to 1.8.2 has a missing authorization vulnerability, allowing unauthenticated or low-privileged users to access restricted functionality.

Vulnerability

Description The VikBooking Hotel Booking Engine & PMS plugin for WordPress suffers from a broken access control vulnerability due to missing authorization checks. This issue affects versions from n/a through 1.8.2, allowing unauthorized access to certain functions that should require higher privileges [1].

Exploitation

Attackers can exploit this vulnerability by sending specially crafted requests to the plugin's endpoints without requiring authentication or with minimal privileges. The vulnerability is classified as low severity and is considered unlikely to be exploited in mass campaigns, though similar issues have been used in automated attacks [1].

Impact

Successful exploitation could allow an unauthenticated or low-privileged attacker to perform actions intended for higher-privileged users, such as modifying hotel booking settings or accessing sensitive information. The CVSS score of 5.3 reflects the moderate impact on confidentiality and integrity [1].

Mitigation

The vulnerability has been patched in version 1.8.3. Users are strongly advised to update to the latest version immediately. For those unable to update, temporary measures such as restricting access to the plugin via web application firewall rules may be considered [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.