{"id":"CVE-2026-88926","published":"2026-09-19T07:16:33.377","lastModified":"2026-09-21T13:34:57.127","description":"The VikRentItems Flexible Rental Management System WordPress plugin before 1.2.4 does not sanitise and escape some of its parameters before using them in SQL statements, allowing unauthenticated users to perform SQL injection attacks.","cvssScore":8.6,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N","cwes":["CWE-89"],"vendors":[],"products":[],"references":[{"url":"https://wpscan.com/vulnerability/da39827b-f087-48f3-baa9-759709a3767e/","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"The flaw allows unauthenticated users to perform SQL injection attacks due to insufficient parameter sanitization in the VikRentItems plugin before 1.2.4, potentially leading to data compromise.","exploitability":"Exploitation is relatively easy as it requires no authentication and can be automated, but requires the plugin to be active and accessible.","blast_radius":"If exploited, it could lead to unauthorized data access or manipulation, impacting the security and integrity of the WordPress site.","remediation":"Upgrade to VikRentItems version 1.2.4 or later.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["sql-injection","wordpress","unauthenticated","sanitization"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-30T09:28:46.903Z"}}