Missing Authorization Vulnerability in RW Elephant Rental Inventory Plugin for WordPress
CVE-2026-4123

4.3MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
22 September 2026

What is CVE-2026-4123?

The RW Elephant Rental Inventory plugin for WordPress contains a vulnerability stemming from a missing capability check in the toggle_cache() function, which is tied to the wp_ajax_toggle_cache AJAX action. This flaw allows authenticated users, with at least Subscriber-level access, to alter the plugin's caching behavior by sending unauthorized POST requests to admin-ajax, compromising the integrity of site performance and behavior. Additionally, the lack of nonce verification further exacerbates the risk, making it imperative for site administrators to ensure their installations are updated to the latest versions.

Affected Version(s)

RW Elephant Rental Inventory 0 <= 2.3.13

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nabil Irawan
.