CVE-2026-16143
7.2 HIGHPublished 2026-08-05 · Updated 2026-08-05
AI risk analysis
- Summary
- The flaw allows unauthenticated attackers to inject arbitrary scripts via the customer email field in the booking checkout form due to insufficient input sanitization and output escaping.
- Exploitability
- Exploitation is relatively easy as it requires control over the customer email input, which can be achieved through social engineering or by manipulating user inputs.
- Blast radius
- If exploited, attackers could inject malicious scripts that execute in users' browsers, potentially leading to data theft or further attacks.
- Prioritized remediation
- Update to a patched version of VikRentItems plugin if available; otherwise, sanitize and escape all input fields thoroughly before storing or displaying them.
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
The VikRentItems – Flexible Rental Management System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the customer email field of the booking checkout form in versions up to, and including, 1.2.1. This is due to insufficient input sanitization and output escaping in the saveorder() function, which stores the raw email value via VikRequest::getString() (applying only sanitize_text_field(), which does not neutralize HTML attribute-breaking characters such as double quotes), and in the editorder template which echoes the stored custmail value into an HTML input element's value attribute without esc_attr(). This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Weaknesses
CWE-79
All references
- https://plugins.trac.wordpress.org/browser/vikrentitems/tags/1.2.1/admin/views/editorder/tmpl/default.php#L499
- https://plugins.trac.wordpress.org/browser/vikrentitems/tags/1.2.1/site/controller.php#L389
- https://plugins.trac.wordpress.org/changeset/3617300/vikrentitems/trunk/admin/views/editorder/tmpl/default.php
- https://www.wordfence.com/threat-intel/vulnerabilities/id/197760d1-395d-4dfb-aaa7-5fc5fc0a1ecb?source=cve
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.