OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-88926

HIGH · CVSS 8.6 EPSS 0.45%

Source: NVD + CISA KEV + EPSS · Published 2026-09-19 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

The VikRentItems Flexible Rental Management System plugin for WordPress prior to version 1.2.4 is vulnerable to SQL injection due to inadequate sanitization and escaping of parameters in SQL statements. This flaw allows unauthenticated users to manipulate database queries, potentially leading to unauthorized data access or modification. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate the risk of exploitation.

CVE
CVE-2026-88926
Severity
HIGH
CVSS
8.6
EPSS
0.45%
WordPress

Original NVD Description

The VikRentItems Flexible Rental Management System WordPress plugin before 1.2.4 does not sanitise and escape some of its parameters before using them in SQL statements, allowing unauthenticated users to perform SQL injection attacks.