RentMy Real-Time Rental Management Plugin, CVE-2026-8690
- CVE, Research URL
- Application
- Published on
- Jun 24, 2026
- Research Description
- The RentMy Real-Time Rental Management Plugin plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.0.4.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to read, create, update, and delete event records stored in the rentmy_events WordPress option, as well as overwrite the rentmy_locationId option.
- Affected versions
-
max 4.0.4.1.
- Status
-
vulnerable
| Previous vulnerability researches |
|---|
| WP Latest Posts (CVE-2026-9620) , Jun 25, 2026 |
| WP Latest Posts (CVE-2016-10913) , Jun 07, 2024 |
| WP Latest Posts (CVE-2024-4135) , Jun 07, 2024 |