CVE-2025-5803
Description
Missing Authorization vulnerability in e4jvikwp VikBooking Hotel Booking Engine & PMS vikbooking.This issue affects VikBooking Hotel Booking Engine & PMS: from n/a through <= 1.8.2.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
VikBooking Hotel Booking Engine & PMS plugin up to 1.8.2 has a missing authorization vulnerability, allowing unauthenticated or low-privileged users to access restricted functionality.
Vulnerability
Description The VikBooking Hotel Booking Engine & PMS plugin for WordPress suffers from a broken access control vulnerability due to missing authorization checks. This issue affects versions from n/a through 1.8.2, allowing unauthorized access to certain functions that should require higher privileges [1].
Exploitation
Attackers can exploit this vulnerability by sending specially crafted requests to the plugin's endpoints without requiring authentication or with minimal privileges. The vulnerability is classified as low severity and is considered unlikely to be exploited in mass campaigns, though similar issues have been used in automated attacks [1].
Impact
Successful exploitation could allow an unauthenticated or low-privileged attacker to perform actions intended for higher-privileged users, such as modifying hotel booking settings or accessing sensitive information. The CVSS score of 5.3 reflects the moderate impact on confidentiality and integrity [1].
Mitigation
The vulnerability has been patched in version 1.8.3. Users are strongly advised to update to the latest version immediately. For those unable to update, temporary measures such as restricting access to the plugin via web application firewall rules may be considered [1].
AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.