CyberRota Analysis
AI-GeneratedThe VikRentItems Flexible Rental Management System plugin for WordPress prior to version 1.2.4 is vulnerable to SQL injection due to inadequate sanitization and escaping of parameters in SQL statements. This flaw allows unauthenticated users to manipulate database queries, potentially leading to unauthorized data access or modification. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate the risk of exploitation.
Original NVD Description
The VikRentItems Flexible Rental Management System WordPress plugin before 1.2.4 does not sanitise and escape some of its parameters before using them in SQL statements, allowing unauthenticated users to perform SQL injection attacks.