CVE-2022-27862

CRITICAL

Vikwp Vikbooking Hotel Booking Engine... - Unrestricted File Upload

Title source: rule
STIX 2.1

Description

Arbitrary File Upload leading to RCE in E4J s.r.l. VikBooking Hotel Booking Engine & PMS plugin <= 1.5.3 on WordPress allows attackers to upload and execute dangerous file types (e.g. PHP shell) via the signature upload on the booking form.

References (2)

Core 2

Scores

CVSS v3 9.8
EPSS 0.0117
EPSS Percentile 78.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-434
Status published
Products (2)
E4J s.r.l./VikBooking Hotel Booking Engine & PMS (WordPress plugin) <= 1.5.3 - 1.5.3
vikwp/vikbooking_hotel_booking_engine_\&_property_management_system_plugin < 1.5.3
Published Apr 19, 2022
Tracked Since Feb 18, 2026