CVE-2026-27432: WordPress WP Rentals theme < 3.16.0 - Insecure Direct Object References (IDOR) vulnerability
Authorization Bypass Through User-Controlled Key vulnerability in sc Internet Vivoo WP Rentals allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects WP Rentals: from n/a before 3.16.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress WP Rentals themeto a version that resolves this vulnerability.Fixed in 3.16.0
Event History
Frequently Asked Questions
What level of access does an attacker need?
An attacker needs network access and low-level privileges. No user interaction is required, and the attack complexity is rated low.
What is the expected security impact?
The reported impact is limited to integrity and availability, both rated low. No confidentiality impact is indicated.
Which installations should be considered affected?
WP Rentals versions before 3.16.0 should be considered affected. The available information does not identify an earlier fixed or unaffected version range.
How can I determine whether my site is affected?
Check the installed WP Rentals theme version. If it is earlier than 3.16.0, it falls within the reported affected range.