What is CVE-2026-16143?
CVE-2026-16143 is a Stored XSS vulnerability in the VikRentItems WordPress plugin via the customer email field in the booking checkout form, affecting versions up to 1.2.1. Insufficient input sanitization and output escaping allow unauthenticated attackers to execute scripts in users' browsers. Users should update the plugin to the latest version immediately.
Azərbaycanca: CVE-2026-16143, WordPress-in VikRentItems plaginində sifariş formasının e-poçt sahəsi vasitəsilə Stored XSS zəifliyidir. Bu, 1.2.1 və əvvəlki versiyalara təsir edir və autentifikasiyasız hücumçuya istifadəçi brauzerində zərərli skript icra etməyə imkan verir. İstifadəçilərə plagini dərhal ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which versions of the VikRentItems plugin are affected by CVE-2026-16143?
This Stored XSS vulnerability affects plugin versions up to and including 1.2.1.
How can CVE-2026-16143 be mitigated?
Users should update the VikRentItems plugin to the latest version immediately.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.