VikRentItems Flexible Rental Management System < 1.2.4 - Unauthenticated SQLi
Summary
| CVE | CVE-2026-88926 |
|---|---|
| State | PUBLISHED |
| Assigner | WPScan |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-19 07:16:33 UTC |
| Updated | 2026-09-19 07:16:33 UTC |
| Description | The VikRentItems Flexible Rental Management System WordPress plugin before 1.2.4 does not sanitise and escape some of its parameters before using them in SQL statements, allowing unauthenticated users to perform SQL injection attacks. |
Risk And Classification
Problem Types: CWE-89 SQL Injection
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Unknown | VikRentItems Flexible Rental Management System | affected 1.2.4 semver | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| wpscan.com/vulnerability/da39827b-f087-48f3-baa9-759709a3767e | [email protected] | wpscan.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Artus KG and Shhriyash (en)
CNA: WPScan (en)
There are currently no legacy QID mappings associated with this CVE.