CRITICAL
9.8 CVE-2026-62054 Published 10 Oct 2026
Yacht Rental Plugin PHP Object Injection Vulnerability
Worried this affects your website?
A vulnerability has been disclosed in Yacht Rental versions up to and including 2.6. It allows unauthenticated PHP object injection.
Affected details:
- Affected versions: 2.6 and earlier
- Attack requirement: unauthenticated
- Vulnerability type: PHP object injection
Reference: CVE-2026-62054 on NVD
← Back to Security News