CVE-2026-4123: RW Elephant Rental Inventory <= 2.3.13 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Modification via 'toggle_cache' AJAX Action

Published Sep 22, 2026
·
Updated

The RW Elephant Rental Inventory plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 2.3.13. This is due to a missing capability check on the togglecache() function which is hooked to the wpajaxtogglecache AJAX action. The function also lacks nonce verification. This makes it possible for authenticated attackers, with Subscriber-level access and above, to toggle the plugin's cache setting on or off by sending a POST request to admin-ajax.

Affected Software

1 affected component
RW Elephant Rental Inventory<=2.3.13

Event History

Sep 22, 2026
CVE Published
via MITRE·07:41 AM
Data Sourced
via MITRE·07:41 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

Any authenticated WordPress user with at least the Subscriber role can exploit it. The attacker does not need administrative privileges or user interaction.

2

What access does an attacker need to modify the setting?

The attacker needs a valid authenticated WordPress session and the ability to send a POST request to the site's admin-ajax endpoint. No nonce verification or plugin capability check is required for the affected action.

3

What can an attacker change?

An attacker can toggle the RW Elephant Rental Inventory plugin's cache setting on or off. The reported impact is unauthorized modification of that setting; no confidentiality or availability impact is identified.

4

Which plugin versions are affected?

All versions up to and including 2.3.13 are affected.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203