VYPR
Unrated severityNVD Advisory· Published Sep 19, 2026

CVE-2026-88926

CVE-2026-88926

Description

The VikRentItems Flexible Rental Management System WordPress plugin before 1.2.4 does not sanitise and escape some of its parameters before using them in SQL statements, allowing unauthenticated users to perform SQL injection attacks.

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.