CVE-2026-88926EPSS p36.6%
CVE-2026-88926CVE-2026-88926
Description
The VikRentItems Flexible Rental Management System WordPress plugin before 1.2.4 does not sanitise and escape some of its parameters before using them in SQL statements, allowing unauthenticated users to perform SQL injection attacks.
Scoring
| CVSS | 8.6 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N |
| EPSS | 0.45% probability of exploitation · percentile 36.6% · 2026-10-06T12:00:23Z |
| Last modified | 2026-09-21 |