CVE-2026-88926: VikRentItems Flexible Rental Management System < 1.2.4 - Unauthenticated SQLi
Published Sep 19, 2026
·Updated
The VikRentItems Flexible Rental Management System WordPress plugin before 1.2.4 does not sanitise and escape some of its parameters before using them in SQL statements, allowing unauthenticated users to perform SQL injection attacks.
Affected Software
1 affected component
WordPress plugin VikRentItems Flexible Rental Management System<1.2.4
Event History
Sep 19, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Frequently Asked Questions
1
Which installations are affected?
WordPress sites using the VikRentItems Flexible Rental Management System plugin before version 1.2.4 are affected.
2
Does exploitation require a WordPress account or other authentication?
No. The issue can be exploited by unauthenticated users.
3
What should teams do if they cannot update immediately?
The provided data does not identify a workaround or mitigation other than moving to version 1.2.4 or later.