CVE-2026-84835: WordPress Rentsyst plugin <= 2.1.2 - Broken Access Control vulnerability
Missing Authorization vulnerability in DimaFreund Rentsyst allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects Rentsyst: from n/a through 2.1.2.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Rentsyst pluginto a version that resolves this vulnerability.Fixed in 2.1.2
Event History
Frequently Asked Questions
Who can exploit this issue?
The vector is network-accessible and requires no privileges or user interaction. An unauthenticated remote attacker may be able to exploit the affected access-control weakness.
Which Rentsyst versions are affected?
The issue affects DimaFreund Rentsyst versions through 2.1.2. The available data does not identify a fixed version.
What security impact is documented?
The documented severity is medium, with a CVSS score of 5.3. The vector indicates low confidentiality impact and no documented integrity or availability impact.