Stored Cross-Site Scripting Vulnerability in VikRentItems Rental Management Plugin for WordPress
CVE-2026-16143

7.2HIGH

What is CVE-2026-16143?

The VikRentItems - Flexible Rental Management System plugin for WordPress is susceptible to a Stored Cross-Site Scripting vulnerability. This issue arises from insufficient sanitization of input and inadequate output encoding in the saveorder() function, particularly regarding the handling of customer email data in the booking checkout form. Attackers can exploit this weakness by injecting malicious scripts into the customer email field, which gets stored and executed on pages accessed by users, potentially leading to unauthorized actions or data breaches.

Affected Version(s)

VikRentItems Flexible Rental Management System 0 <= 1.2.1

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

nthng
.