CVE-2026-27434: WordPress WP Rentals theme <= 3.14.2 - Broken Access Control vulnerability
Missing Authorization vulnerability in sc Internet Vivoo WP Rentals wprentals allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Rentals: from n/a through 3.14.2.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
The CVSS vector indicates it can be exploited remotely over the network without authentication or user interaction. The described impact is limited to integrity; no confidentiality or availability impact is listed.
Which installations are affected?
WP Rentals versions through 3.14.2 are affected. The available data does not state whether any particular default configuration or feature must be enabled.
What access could an attacker gain or change?
The issue is described as missing authorization caused by incorrectly configured access-control security levels. The available information does not identify the specific function, endpoint, or data that an attacker could modify.