rootpwn

high · CVSS v3 8.6 · EPSS 0.00177

CVE-2026-88926

The VikRentItems Flexible Rental Management System plugin for WordPress prior to version 1.2.4 fails to properly sanitize and escape user-su

Overview

The VikRentItems Flexible Rental Management System plugin for WordPress prior to version 1.2.4 fails to properly sanitize and escape user-supplied parameters before incorporating them into SQL queries. This flaw enables unauthenticated remote attackers to execute arbitrary SQL commands against the underlying database. It matters because successful exploitation could lead to unauthorized access, data modification, or complete compromise of the WordPress site.

Description

The VikRentItems Flexible Rental Management System WordPress plugin before 1.2.4 does not sanitise and escape some of its parameters before using them in SQL statements, allowing unauthenticated users to perform SQL injection attacks.

Impact

This vulnerability impacts the confidentiality, integrity, and availability of the affected WordPress site. Unauthenticated malicious actors can leverage the SQL injection vector to read sensitive database contents, including user credentials and plugin data. Administrators and site owners are directly impacted as their web applications become susceptible to full database compromise and potential remote code execution chains.

Remediation

Update the VikRentItems Flexible Rental Management System plugin to version 1.2.4 or later immediately. Ensure that Web Application Firewalls (WAF) are configured to detect and block common SQL injection signatures targeting WordPress plugins. Review database query logs for unusual activities or unauthorized queries originating from unauthenticated sessions.

Risk context

The vulnerability carries a high CVSS v3 score of 8.6, reflecting its severity due to unauthenticated exploitation potential. While the current EPSS score is relatively low at 0.00177, public availability of the vulnerability necessitates prompt patching to prevent opportunistic attacks.

Affected products

  • E4J VikRentItems Plugin
  • WordPress VikRentItems Flexible Rental Management System

Scores

Severity
high
CVSS v2
7.8
CVSS v3
8.6
CVSS v4
EPSS
0.00177

SQL Injection WordPress Plugin Unauthenticated High Severity Web Application

← All CVEs