← Back to search

CVE-2026-16143

7.2 HIGH

Published 2026-08-05 · Updated 2026-08-05

AI risk analysis

Summary
The flaw allows unauthenticated attackers to inject arbitrary scripts via the customer email field in the booking checkout form due to insufficient input sanitization and output escaping.
Exploitability
Exploitation is relatively easy as it requires control over the customer email input, which can be achieved through social engineering or by manipulating user inputs.
Blast radius
If exploited, attackers could inject malicious scripts that execute in users' browsers, potentially leading to data theft or further attacks.
Prioritized remediation
Update to a patched version of VikRentItems plugin if available; otherwise, sanitize and escape all input fields thoroughly before storing or displaying them.
xsswebsanitizationinput

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

The VikRentItems – Flexible Rental Management System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the customer email field of the booking checkout form in versions up to, and including, 1.2.1. This is due to insufficient input sanitization and output escaping in the saveorder() function, which stores the raw email value via VikRequest::getString() (applying only sanitize_text_field(), which does not neutralize HTML attribute-breaking characters such as double quotes), and in the editorder template which echoes the stored custmail value into an HTML input element's value attribute without esc_attr(). This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N

Weaknesses

CWE-79

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.