VikRentCar Car Rental Management System <= 1.4.5 - Unauthenticated Insecure Direct Object Reference
medium
The VikRentCar Car Rental Management System plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.4.5 due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 1.4.5
- Fixed in:
- 1.4.6
- Disclosed:
- Jun 10, 2026
CVE-2026-52699 on NVD →
VikRentCar Car Rental Management System [vikrentcar] < 1.4.5
unknown
[en] The VikRentCar Car Rental Management System plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'month' parameter in all versions up to, and including, 1.4.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes...
- Affected:
- up to 1.4.5
- Fixed in:
- 1.4.5
- Disclosed:
- Dec 2, 2025
CVE-2025-13724 on NVD →
VikRentCar Car Rental Management System <= 1.4.4 - Authenticated (Author+) SQL Injection via 'month' Parameter
high
The VikRentCar Car Rental Management System plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'month' parameter in all versions up to, and including, 1.4.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it p...
- CVSS:
- 7.5
- Affected:
- up to 1.4.4
- Fixed in:
- 1.4.5
- Disclosed:
- Dec 1, 2025
CVE-2025-13724 on NVD →
VikRentCar Car Rental Management System <= 1.4.3 - Authenticated (Administrator+) Arbitrary File Upload
high
The VikRentCar Car Rental Management System plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the do_updatecar and createcar functions in all versions up to, and including, 1.4.3. This makes it possible for authenticated attackers, with Administrator-level access and ab...
- CVSS:
- 7.2
- Affected:
- up to 1.4.3
- Fixed in:
- 1.4.4
- Disclosed:
- Jul 3, 2025
CVE-2025-5322 on NVD →
VikRentCar Car Rental Management System [vikrentcar] < 1.4.3
unknown
[en] The VikRentCar Car Rental Management System plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.2. This is due to missing or incorrect nonce validation on the 'save' function. This makes it possible for unauthenticated attackers to change plugin access privile...
- Affected:
- up to 1.4.3
- Fixed in:
- 1.4.3
- Disclosed:
- Mar 8, 2025
CVE-2024-11640 on NVD →
VikRentCar Car Rental Management System <= 1.4.2 - Cross-Site Request Forgery to Authenticated (Subscriber+) Arbitrary File Upload
high
The VikRentCar Car Rental Management System plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.2. This is due to missing or incorrect nonce validation on the 'save' function. This makes it possible for unauthenticated attackers to change plugin access privileges v...
- CVSS:
- 8.8
- Affected:
- up to 1.4.2
- Fixed in:
- 1.4.3
- Disclosed:
- Mar 7, 2025
CVE-2024-11640 on NVD →
VikRentCar Car Rental Management System [vikrentcar] < 1.4.1
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in E4J s.R.L. VikRentCar allows SQL Injection.This issue affects VikRentCar: from n/a through 1.4.0.
- Affected:
- up to 1.4.1
- Fixed in:
- 1.4.1
- Disclosed:
- Aug 29, 2024
CVE-2024-39653 on NVD →
VikRentCar <= 1.4.0 - Unauthenticated SQL Injection
critical
The VikRentCar plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.4.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into...
- CVSS:
- 10
- Affected:
- up to 1.4.0
- Fixed in:
- 1.4.1
- Disclosed:
- Aug 1, 2024
CVE-2024-39653 on NVD →
VikRentCar Car Rental Management System <= 1.3.1 - Cross-Site Request Forgery
medium
The VikRentCar Car Rental Management System plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.1. This is due to missing or incorrect nonce validation on the cancelrequest task. This makes it possible for unauthenticated attackers to cancel requests via a forged r...
- CVSS:
- 4.3
- Affected:
- up to 1.3.1
- Fixed in:
- 1.3.2
- Disclosed:
- Jul 20, 2024
CVE-2024-1845 on NVD →
VikRentCar Car Rental Management System [vikrentcar] < 1.3.2
unknown
[en] The VikRentCar Car Rental Management System WordPress plugin before 1.3.2 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks
- Affected:
- up to 1.3.2
- Fixed in:
- 1.3.2
- Disclosed:
- Jul 11, 2024
CVE-2024-1845 on NVD →
VikRentCar Car Rental Management System [vikrentcar] < 1.3.3
unknown
[en] Exposure of Sensitive Information to an Unauthorized Actor vulnerability in E4J s.R.L. VikRentCar.This issue affects VikRentCar: from n/a through 1.3.2.
- Affected:
- up to 1.3.3
- Fixed in:
- 1.3.3
- Disclosed:
- Apr 24, 2024
CVE-2024-32780 on NVD →
VikRentCar Car Rental Management System <= 1.3.2 - Information Exposure
medium
The VikRentCar Car Rental Management System plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.3.2 due to publicly accessible PDF files. This makes it possible for unauthenticated attackers to extract potentially sensitive information via PDFs.
- CVSS:
- 5.3
- Affected:
- up to 1.3.2
- Fixed in:
- 1.3.3
- Disclosed:
- Apr 22, 2024
CVE-2024-32780 on NVD →
VikRentCar Car Rental Management System [vikrentcar] < 1.3.1
unknown
[en] Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in E4J s.R.L. VikRentCar Car Rental Management System plugin <= 1.3.0 versions.
- Affected:
- up to 1.3.1
- Fixed in:
- 1.3.1
- Disclosed:
- Apr 6, 2023
CVE-2023-23998 on NVD →
VikRentCar Car Rental Management System <= 1.3.0 - Authenticated (Admin+) Cross Site Scripting
medium
The VikRentCar Car Rental Management System plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.3.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with admin-level permissions and above, to inject arbitrary web s...
- CVSS:
- 5.5
- Affected:
- up to 1.3.0
- Fixed in:
- 1.3.1
- Disclosed:
- Jan 20, 2023
CVE-2023-23998 on NVD →
VikRentCar Car Rental Management System [vikrentcar] < 1.1.10
unknown
[en] The VikRentCar Car Rental Management System WordPress plugin before 1.1.10 does not sanitise the 'Text Next to Icon' field when adding or editing a Characteristic, allowing high privilege users such as admin to use XSS payload in it, leading to an authenticated Stored Cross-Site Scripting issue
- Affected:
- up to 1.1.10
- Fixed in:
- 1.1.10
- Disclosed:
- Aug 16, 2021
CVE-2021-24519 on NVD →
VikRentCar Car Rental Management System < 1.1.10 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The VikRentCar Car Rental Management System WordPress plugin before 1.1.10 does not sanitise the 'Text Next to Icon' field when adding or editing a Characteristic, allowing high privilege users such as admin to use XSS payload in it, leading to an authenticated Stored Cross-Site Scripting issue.
- CVSS:
- 5.5
- Affected:
- up to 1.1.10
- Fixed in:
- 1.1.10
- Disclosed:
- Jul 19, 2021
CVE-2021-24519 on NVD →
VikRentCar Car Rental Management System [vikrentcar] < 1.1.7
unknown
[en] In the VikRentCar Car Rental Management System WordPress plugin before 1.1.7, there is a custom filed option by which we can manage all the fields that the users will have to fill in before saving the order. However, the field name is not sanitised or escaped before being output back in the page, leading to a stor...
- Affected:
- up to 1.1.7
- Fixed in:
- 1.1.7
- Disclosed:
- Jul 6, 2021
CVE-2021-24388 on NVD →
Vik Rent Car <= 1.1.6 - Cross-Site Request Forgery to Stored Cross-Site Scripting
medium
In the VikRentCar Car Rental Management System WordPress plugin before 1.1.7, there is a custom field option by which we can manage all the fields that the users will have to fill in before saving the order. However, the field name is not sanitised or escaped before being output back in the page, leading to a stored Cr...
- CVSS:
- 6.1
- Affected:
- up to 1.1.6
- Fixed in:
- 1.1.7
- Disclosed:
- Jun 14, 2021
CVE-2021-24388 on NVD →
VikRentCar Car Rental Management System [vikrentcar] < 1.4.4
unknown
- Affected:
- up to 1.4.4
- Fixed in:
- 1.4.4
CVE-2025-5322 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database