PT-2025-50900 · WordPress · Vikrentitems Flexible Rental Management System

Athiwat Tiprasaharn

·

Published

2025-12-12

·

Updated

2025-12-12

·

CVE-2025-14049

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions VikRentItems Flexible Rental Management System versions up to and including 1.2.0
Description The VikRentItems Flexible Rental Management System plugin for WordPress is susceptible to Reflected Cross-Site Scripting through the delto parameter. Insufficient input sanitization and output escaping allow unauthenticated attackers to inject arbitrary web scripts into pages. Successful exploitation requires tricking a user into performing an action, such as clicking a malicious link. The API endpoint affected is not explicitly mentioned.
Recommendations Versions up to and including 1.2.0 should be updated to a newer, fixed version when available.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-14049

Affected Products

Vikrentitems Flexible Rental Management System