Executive brief
Rentsyst is a WordPress plugin used for rental property and booking management. A broken access control vulnerability allows unauthenticated users to access pages and perform actions they should not be permitted to, potentially exposing other users' rental data, bookings, and sensitive information without authorization.
Technical details
This vulnerability is a broken access control issue (CWE-639) in the Rentsyst WordPress plugin affecting versions through 2.1.5. The plugin fails to properly validate authorization checks on sensitive endpoints, allowing unauthenticated users to access restricted pages and perform unauthorized actions. An attacker can exploit this via network requests without authentication to view or manipulate other users' data. The vulnerability requires no user interaction and is network-accessible. No official patch is currently available; administrators should update to a patched version when available or disable the plugin.
Affected products
- DimaFreund Rentsyst through 2.1.5
Timeline
- 2026-09-02: disclosed