WordPress VikBooking Hotel Booking Engine & PMS plugin <= 1.5.3 - Arbitrary File Upload leading to RCE
Vulnerability Description
Arbitrary File Upload leading to RCE in E4J s.r.l. VikBooking Hotel Booking Engine & PMS plugin <= 1.5.3 on WordPress allows attackers to upload and execute dangerous file types (e.g. PHP shell) via the signature upload on the booking form.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-27862
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Vulnerability discovered by Huli (Patchstack Alliance)
References
More from E4J s.r.l.
View All →Affected Vendor
E4J s.r.l.
View all reports →