Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2022-27862: VikBooking Hotel Booking Engine & PMS

Sensitive Information Exposure in E4J s.r.l. VikBooking Hotel Booking Engine & PMS plugin <= 1.5.3 on WordPress allows attackers to upload and execute dangerous file types (e.g. PHP shell) via the signature upload on the booking form.

CVE
#web#windows#google
  • Details
  • Reviews
  • Installation
  • Support
  • Development

Vik Booking for WordPress

The famous Booking Engine and PMS online software for accommodations is now available also for WordPress as a native Plugin!

If you are looking for a reliable reservation system for a Hotel, B&B, Villa, Apartments, Hostel or any similar accommodation, then you have found the right plugin. In fact, Vik Booking is a PCI-DSS and OpenTravel compliant hotel Booking Engine used by thousands of properties every day.

This is the free version of the plugin, but you can upgrade to the Pro version at any time from your wp-admin section. Experience the power of a true and internal Booking Engine that competes with the best ones of the world!

The Pro version is compatible with Vik Channel Manager, the first and only native Channel Manager for WordPress, listed as a Premier Partner of Booking.com since 2018 among the top 20 systems worldwide. Full API connections available with the most famous OTAs such as Airbnb, Expedia and Google Hotel for their new Free Booking Links! Beware of “fake” Channel Manager plugins that only offer unreliable iCal synchronizations with no private access to the OTA’s APIs.

Vik Booking was born in 2010 for a different web-software (CMS) than WordPress, and that’s how it became famous. The same powerful framework is now (since 2018) at the service of all webmasters, designers and web-agencies that work with WordPress. It’s definitely the hotel reservation plugin that you, or your client, were looking for.

Visit VikWP.com for more details. Interested in our full solution comprehensive of the Channel Manager? Visit also E4jConnect.

Some of the unique features

  • Custom Rate Plans (Refundable, Flexible, Non Refundable rates)
  • Rooms, Room Types and Sub-Units management functions
  • Availability Calendars and Occupancy Overview
  • Bookings Management made right
  • Feature-rich Back-end section
  • Front-end customizable booking process
  • 8 different Views for the front-end (8 Types of Shortcode for your pages)
  • Compliant with any Pricing Model: Occupancy, Nightly, LOS, OBP etc…
  • Housekeeping features with Tableaux, festivities and room-day notes
  • Permissions/ACL Management functions for the various WP Users Roles
  • Multi-language support with built-in translation functions
  • Channel Manager compatible. We are a certified Channel Manager provider (e4jConnect).
  • Google Hotel Ads certified for Free Booking Links.

Some of Pro version features

  • Seasonal Rates and Rates Calendar with 1-click modification
  • Booking Restrictions: Min, Max LOS, CTA/CTD, Forced Arrival/Departure days
  • Custom Payment Gateways (over 60 available on VikWP.com)
  • SMS Gateways for automated notifications
  • Custom Cron Jobs Scheduling for automated tasks (reminders, invoices)
  • Customers Management functions, sales channels and commissions
  • Graphs and Statistics
  • Custom Options, Extra Services, Extra Fees
  • Add, Remove or Switch rooms from existing bookings
  • PMS Reports with extendable framework (built-in services for various countries)
  • Electronic invoices extendable framework compliant with Italy (Agenzia delle Entrate) and Greece (myDATA ΑΑΔΕ).
  • Registration functions: check-in, check-out, no-show
  • Our award winning solution of Booking Engine + PMS and Channel Manager is all you need on your WordPress website.

Interested in, curious about the Pro version?

You should take a look with your own eyes at the demo website to see what you can do with Vik Booking. Do not stop at the front-end though, make sure to visit the wp-admin section too.

  1. Front-end Demo Website
  2. Admin Demo Website

This plugin provides 1 block.

  • VikBooking Hotel Booking Engine & PMS

Installation through the WordPress Plugins Browser

  • Search for “Vik Booking” in the Add Plugin section of your website back-end
  • Install the Plugin by clicking on the apposite button
  • Activate the Plugin by using the apposite activation button
  • A link to access and configure Vik Booking will be visible in the left-menu
  • Enjoy it

Alternative Installation Method

You can only install the free version of Vik Booking, not the Pro version. If for some reasons the WordPress Repository installation won’t work, you can contact us to receive the zip installer file and upload it via FTP onto your server.

  • Download the installer zip file from VikWP.com
  • Unzip the archive on your computer’s local drive
  • Upload via FTP the unzipped folder vikbooking onto your /wp-content/plugins directory
  • Log in to your wp-admin section and activate the plugin

Is upgrading to Pro mandatory?

No, not at all. However, it took our company 8 years to build the Pro version and we are willing to spend a lot more years of work on this software. We encourage you to evaluate the free version first, and then upgrade to Pro to unlock its potential.

Why some functions are not available in the free version?

We are a software development company listed as a certified Channel Manager Provider by the major OTAs of the world. We work to deliver a full software solution for CMS and Web Software like WordPress as a valid alternative to the same proprietary and external systems. We make money by selling licenses of the Pro version.

Is it worth upgrading to Pro?

Vik Booking is not a one-page plugin. You can build websites worth a lot of money with this plugin. You don’t need anything else to deliver a complete website, if not a Theme and some experience with WordPress.

Can I build a portal of multiple properties/apartments?

No, you can’t! Vik Booking was designed specifically for single properties, or multiple properties managed by the same company. Basically, you cannot build a portal with multiple vendors where certain users should access and manage only their rooms and reservations. Vik Booking is a true booking engine for Hotels, B&Bs, Apartments, Villas and Hostels. It should be installed on the website of the accommodation. Even though permissions for receptionists and managers can be set up, the logic of the software remains single-vendor.
If you are looking for a solution for a real-estate agency (for example) that manages multiple properties on its own, then it’s still fine as long as you don’t need specific users/owners to see or manage their own data because this is not supported.

Can I use Vik Booking with my preferred Theme?

Yes, of course. You are free to install Vik Booking on your website with your own Theme. The plugin will adjust to it thanks to its own CSS framework. It is also possible to work on a custom CSS file to adjust some layouts.

What about Vik Channel Manager or E4JConnect?

Vik Booking is the Booking Engine and PMS plugin, it can work alone on any existing website. However, if you are looking to establish real-time API connections with OTAs like Booking.com, Airbnb, Expedia, Google Hotel Ads etc… then you need to use our full solution, which is composed of a one-time fee to purchase the Pro version of Vik Booking as well as the plugin Vik Channel Manager. The only recurring cost, just like any existing (and real) Channel Manager software, is the one to keep the connection active with the various channels. This is the subscription for our certified and award-winning Channel Manager service called “e4jConnect”. Please notice that all these services are entirely provided by our company, it’s one single company with no third party connections. We are the software developer company as well as the Channel Manager provider. This makes a big difference.

Ormai 6 mesi che utilizziamo il sistema e ci troviamo alla grande. Ha tutto quello che ci serve per la gestione quotidiana della struttura. Ogni aggiornamento vengono aggiunte nuove funzionalità e il support è super disponibile.

I have used vikbooking in both joomla and wordpress version. This is a great product that does what most hotel/hostel business want to keep in-house. Having a great product is never enough without dedicated after-sale support. My personal experience with their support team has been positive throughout. It has been quick and to the point. I also see that their effort has never ceased in constant improvement in their product even though it has been out in the market for years. It shows that they listen to their customers’ needs and strive to give something of value to all future customers. Two thumbs up.

I bought the VikBooking Pro plugin first, then the Channel Manager, then an e4JConnect subscription for a client that needed to manage reservations for a small 5-bungalow property in connection with Booking.com. After a brief learning curve and some great customer support on their part, the hotel receives bookings both directly and in sync with their main channel so we are very happy with the end result. The UI is friendly and simple enough for any private villa or independent multi-room property. It also adds the needed pages to your WP site. If you’re just getting started, this is a good easy-to-learn solution. As far as pricing, if all you need is the booking engine -VikBooking Pro- and a simple way for customers to pay for their reservations online, it’s fair as it comes with the ability to take payments through PayPal. If you need to manage additional channels and payment gateways, take the time to read through all of the options as the costs will rack up once you begin adding all the extras needed to fully operate a hotel successfully. E.g.: The booking engine, the channel manager, the required e4jConnect subscription(s) needed per channel (Airbnb, Booking.com, etc.), plus any additional payment gateway such as Stripe. Overall, I give it 5-starts for its easy setup, ease of use, and in a big way, the over-the-top customer support provided during our setup. I will be recommending them again for future projects.

Great plugin, really well thought out. This deserves way more credit than it gets!

The plugin offers tons of great features. I would highly recommend using it for your hotel booking website.

Very powerful plugin, with a user friendly interface and easy to manage but above all a level support that allows you to face any type of problem.

Read all 39 reviews

“VikBooking Hotel Booking Engine & PMS” is open source software. The following people have contributed to this plugin.

Contributors

  • e4jvikwp

1.5.6

Release date – 19 April 2022

  • Added support for customer profile picture (avatar).
  • Prevented switch of non refundable rates during booking modification.
  • Sanitized malicious data injections.
  • Fixed compatibility issues with Windows servers.
  • Major core framework release.
  • Dark mode appearance for dark color scheme preferences.
  • Multitask panel to quickly query the system without changing pages.
  • Browser (web push) notifications with real-time alerts.
  • New admin widgets and framework.
  • Reminders with scheduled due dates.
  • Rates flow monitoring for OTA and Website rates.
  • Custom data collection for guests registration.
  • myDATA AADE integration for electronic invoicing in Greece.
  • Inquiry reservations with pending status and auto room-assignment.
  • Backups: import and export an entire configuration from one site to another.
  • Visual (rich text) editor and composer for any email message.
  • New statistics tracking features.
  • Coupon codes with minimum stay filter.
  • New conditional text rules.
  • New permissions for front-end Tableaux and operators.
  • Support (and certification) for Google Hotel Free Booking Links!!! (Vik Channel Manager + E4JConnect subscription required)

Earlier versions

For further details about older versions, please refer to the changelog.md file of the plugin.

Related news

CVE-2022-27863: WordPress VikBooking Hotel Booking Engine & PMS plugin <= 1.5.3 - Sensitive Data Exposure vulnerability - Patchstack

Sensitive Information Exposure in E4J s.r.l. VikBooking Hotel Booking Engine & PMS plugin <= 1.5.3 on WordPress allows attackers to get the booking data by guessing / brute-forcing easy predictable booking IDs via search POST requests.

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907