PatchSiren cyber security CVE debrief
CVE-2026-8690 rentmy CVE debrief
The RentMy Real-Time Rental Management Plugin for WordPress has an authorization bypass vulnerability in all versions up to and including 4.0.4.1. The plugin fails to properly verify user authorization for certain actions, allowing unauthenticated attackers to read, create, update, and delete event records stored in the rentmy_events WordPress option. Additionally, attackers can overwrite the rentmy_locationId option. This vulnerability has a CVSS score of 5.3 and a severity rating of MEDIUM.
- Vendor
- rentmy
- Product
- RentMy Real-Time Rental Management Plugin
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-06-24
- Original CVE updated
- 2026-06-25
- Advisory published
- 2026-06-24
- Advisory updated
- 2026-06-25
Who should care
WordPress users who have installed the RentMy Real-Time Rental Management Plugin, especially those with versions up to and including 4.0.4.1, should be aware of this vulnerability. Site administrators and security teams should prioritize patching or mitigating this vulnerability to prevent potential unauthorized access to event records and location settings.
Technical summary
The RentMy Real-Time Rental Management Plugin for WordPress is vulnerable to an authorization bypass due to inadequate verification of user authorization. This allows unauthenticated attackers to perform actions such as reading, creating, updating, and deleting event records stored in the rentmy_events WordPress option. The vulnerability also enables attackers to overwrite the rentmy_locationId option. The issue is tracked under CVE-2026-8690 and has a CVSS score of 5.3, indicating a MEDIUM severity level.
Defensive priority
Patching the RentMy Real-Time Rental Management Plugin to a version beyond 4.0.4.1 is crucial to mitigate this authorization bypass vulnerability. In the interim, site administrators can implement additional monitoring and logging to detect potential exploitation attempts.
Recommended defensive actions
- Patch the RentMy Real-Time Rental Management Plugin to the latest version.
- Implement Web Application Firewall (WAF) rules to detect and block suspicious traffic.
- Enhance monitoring and logging to detect potential exploitation attempts.
- Conduct regular security audits and vulnerability assessments.
- Restrict access to sensitive areas of the WordPress site.
Evidence notes
The CVE record for CVE-2026-8690 was obtained from the official CVE.org website. Additional details were sourced from the National Vulnerability Database (NVD) and Wordfence security research. The vulnerability is caused by inadequate authorization checks in the RentMy Real-Time Rental Management Plugin for WordPress.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-8690 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-8690
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-8690 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-8690
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/rentmy-online-rental-shop/trunk/includes/class-rentmy-ajax.php
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/rentmy-online-rental-shop/trunk/includes/class-rentmy-ajax.php
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/rentmy-online-rental-shop/trunk/includes/class-rentmy-ajax.php
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/rentmy-online-rental-shop/trunk/includes/class-rentmy-ajax.php
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.