CRITICAL 9.8 CVE-2026-62054 Published 10 Oct 2026

Yacht Rental Plugin PHP Object Injection Vulnerability

Worried this affects your website?

A vulnerability has been disclosed in Yacht Rental versions up to and including 2.6. It allows unauthenticated PHP object injection.

Affected details:

  • Affected versions: 2.6 and earlier
  • Attack requirement: unauthenticated
  • Vulnerability type: PHP object injection

Reference: CVE-2026-62054 on NVD

← Back to Security News