CVE-2026-8690 Details
Description
The RentMy Real-Time Rental Management Plugin plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.0.4.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to read, create, update, and delete event records stored in the rentmy_events WordPress option, as well as overwrite the rentmy_locationId option.
A vulnerability exists in the RentMy Real-Time Rental Management Plugin for WordPress, affecting all versions up to and including 4.0.4.1. The issue stems from the plugin's failure to properly verify user authorization for certain actions. This flaw allows unauthenticated attackers to read, create, update, and delete event records in the WordPress 'rentmy_events' option. Additionally, attackers can overwrite the 'rentmy_locationId' option.
Users are advised to update the RentMy Real-Time Rental Management Plugin to version 1.0.3, which includes nonce verification, capability checks, and input sanitization for AJAX handlers. This version has been tested up to WordPress 7.0.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 24, 2026CISA-ADP
Assessed Jun 24, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-862 | Missing Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| RentMy Real-Time Rental Management | <= 4.0.4.1 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 24, 2026 | CVE Modified | CISA-ADP |
| Jun 24, 2026 | New CVE Received | [email protected] |
Volerion