Junglewise Threat Intelligence

CVE-2026-16143: VikRentItems Stored Cross-Site Scripting in customer email field

CVE-2026-16143 · Severity: high · CVSS 7.2 · Published 2026-08-05

Executive brief

The VikRentItems plugin for WordPress, used to manage rental bookings and reservations, contains a flaw that allows attackers to inject malicious scripts into booking records via the customer email field. When administrators or other users later view these bookings, the malicious scripts execute in their browsers, potentially compromising their accounts, stealing session data, or modifying booking information.

Technical details

The vulnerability is a Stored Cross-Site Scripting (XSS) flaw in the VikRentItems plugin versions up to 1.2.1. The root cause is insufficient input sanitization in the saveorder() function, which uses sanitize_text_field() to process the customer email field—a function that does not neutralize HTML attribute-breaking characters such as double quotes. Additionally, the editorder template echoes the stored custmail value directly into an HTML input element's value attribute without using esc_attr() for proper escaping. An unauthenticated attacker can inject arbitrary JavaScript into the customer email field during booking checkout. The malicious payload persists in the database and executes in the browsers of any user (typically administrators or support staff) who view the affected booking record.

Affected products

  • VikRentItems VikRentItems up to 1.2.1

Timeline

  • 2026-08-05: disclosed: CVE-2026-16143 published

References