Junglewise Threat Intelligence

CVE-2026-88926: VikRentItems Flexible Rental Management System SQL injection

CVE-2026-88926 · Severity: high · CVSS 8.6 · Published 2026-09-19

Executive brief

VikRentItems is a WordPress plugin that manages property rental reservations and booking workflows. The plugin fails to properly sanitize user inputs before using them in database queries, allowing attackers to inject arbitrary SQL commands without authentication. An attacker could exploit this to extract sensitive data such as renter information, payment details, and booking records from the database.

Technical details

The plugin does not sanitize and escape parameters before inclusion in SQL statements, creating an unauthenticated SQL injection vulnerability. An attacker can submit malicious input through vulnerable parameters to execute arbitrary SQL queries against the WordPress database. The vulnerability was patched in version 1.2.4.

Affected products

  • VikWP VikRentItems Flexible Rental Management System before 1.2.4

Timeline

  • 2026-09-17: disclosed
  • 2026-09-19: advisory
  • 2026-09-17: patched: Fixed in version 1.2.4

References