The VikRentItems Flexible Rental Management System WordPress plugin before 1.2.4 does not sanitise and escape some of its parameters before using them in SQL statements, allowing unauthenticated users to perform SQL injection attacks.
CVE-2026-88926
NONE
EPSS 0.18%
Updated Sep 19, 2026
Unknown
unknown:vikrentitems flexible rental management system
CVE Details
CVE ID
CVE-2026-88926
Published Date
Sep 19, 2026
Vendor
Unknown
Severity
NONE
Exploit Prediction (EPSS)
Probability of Exploit
0.18%
Likelihood of exploitation in next 30 days
Percentile:
7.5th percentile (higher than 7.5% of all CVEs)
Standard patching cycle
Impact
Minimal impact
Source
View Advisory