Impact
The VikRentItems Flexible Rental Management System WordPress plugin before version 1.2.4 fails to sanitise and escape several parameters used in SQL queries. This omission enables unauthenticated users to inject arbitrary SQL through those parameters, potentially allowing data exfiltration, database compromise, or privilege escalation. The vulnerability is a classic example of an injection flaw that can directly affect the confidentiality, integrity, or availability of the application’s underlying data store.
Affected Systems
The affected product is the VikRentItems Flexible Rental Management System WordPress plugin, before version 1.2.4. Anyone running any pre‑1.2.4 build of the plugin on a WordPress site is susceptible, regardless of the installation location or hosting provider.
Risk and Exploitability
The weakness permits unauthenticated exploitation over the web, making it highly exploitable as long as the vulnerable plugin is active. The EPSS score is currently unavailable, and the vulnerability has not been listed in CISA KEV. The lack of authentication requirements and the direct use of user‑controllable parameters indicate a high risk of successful exploitation, which could lead to unauthorized data access or modification. Attackers would likely employ crafted HTTP requests to trigger the injection, subject only to network access to the WordPress installation.
OpenCVE Enrichment