plugin

Js Vehicle Manager Vulnerabilities

3 known security issues reported for the Js Vehicle Manager WordPress plugin. Most recent disclosed Mar 3, 2025.

1 critical

Running Js Vehicle Manager on your site? Check whether your installed version is affected.

Scan your site free

WP Vehicle Manager [js-vehicle-manager] <= 3.1 (unfixed + closed)

unknown

[en] Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in NotFound WP Vehicle Manager allows PHP Local File Inclusion. This issue affects WP Vehicle Manager: from n/a through 3.1.

Affected:
up to 3.1
Fix:
No patched version reported
Disclosed:
Mar 3, 2025

CVE-2025-25109 on NVD →

WP Vehicle Manager [js-vehicle-manager] <= 3.1 (unfixed + closed)

unknown

[en] Missing Authorization vulnerability in DeannaS Embed RSS allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Embed RSS: from n/a through 3.1.

Affected:
up to 3.1
Fix:
No patched version reported
Disclosed:
Feb 7, 2025

CVE-2025-25081 on NVD →

WP Vehicle Manager <= 3.1 - Unauthenticated Local File Inclusion

critical

The WP Vehicle Manager plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.1. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access con...

CVSS:
9.8
Affected:
up to 3.1
Fix:
No patched version reported
Disclosed:
Feb 2, 2025

CVE-2025-25109 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database