A vulnerability labeled as problematic has been found in e4jvikwp VikBooking Hotel Booking Engine & PMS Plugin up to 1.8.13 on WordPress. Impacted is an unknown function. Executing a manipulation of the argument category_id can lead to cross site scripting.
This vulnerability is tracked as CVE-2026-15346. The attack can be launched remotely. No exploit exists.