Product
The VikRentItems WordPress plugin contains a stored XSS vulnerability in the checkout booking form allowing unauthenticated attackers to execute arbitrary scripts in the administrative backend.