Stored Cross-Site Scripting Vulnerability in VikRentItems Rental Management Plugin for WordPress
CVE-2026-16143
7.2HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 5 August 2026
What is CVE-2026-16143?
The VikRentItems - Flexible Rental Management System plugin for WordPress is susceptible to a Stored Cross-Site Scripting vulnerability. This issue arises from insufficient sanitization of input and inadequate output encoding in the saveorder() function, particularly regarding the handling of customer email data in the booking checkout form. Attackers can exploit this weakness by injecting malicious scripts into the customer email field, which gets stored and executed on pages accessed by users, potentially leading to unauthorized actions or data breaches.
Affected Version(s)
VikRentItems Flexible Rental Management System 0 <= 1.2.1