Extension WordPress

Vulnérabilités VikRentCar Car Rental Management System

Cette page rassemble les failles publiées pour VikRentCar Car Rental Management System, leurs plages de versions affectées et les correctifs signalés dans la base locale.

10Vulnérabilités
1Critiques
10Avec correctif
10,0CVSS maximal

Historique de sécurité

CVE et vulnérabilités de VikRentCar Car Rental Management System

10 fiches

CVE-2026-52699 Moyenne · 5,3
VikRentCar Car Rental Management System

VikRentCar Car Rental Management System <= 1.4.5 – Unauthenticated Insecure Direct Object Reference

The VikRentCar Car Rental Management System plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.4.5 due to missing validation on a user controlled key. This makes it possible for…

Versions affectées

*-1.4.5

Correctif

1.4.6

Publication

10/06/2026

CVE-2025-13724 Élevée · 7,5
VikRentCar Car Rental Management System

VikRentCar Car Rental Management System <= 1.4.4 – Authenticated (Author+) SQL Injection via 'month' Parameter

The VikRentCar Car Rental Management System plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'month' parameter in all versions up to, and including, 1.4.4 due to insufficient escaping on the user supplied parameter and…

Versions affectées

*-1.4.4

Correctif

1.4.5

Publication

01/12/2025

CVE-2025-5322 Élevée · 7,2
VikRentCar Car Rental Management System

VikRentCar Car Rental Management System <= 1.4.3 – Authenticated (Administrator+) Arbitrary File Upload

The VikRentCar Car Rental Management System plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the do_updatecar and createcar functions in all versions up to, and including, 1.4.3. This makes it…

Versions affectées

*-1.4.3

Correctif

1.4.4

Publication

03/07/2025

CVE-2024-11640 Élevée · 8,8
VikRentCar Car Rental Management System

VikRentCar Car Rental Management System <= 1.4.2 – Cross-Site Request Forgery to Authenticated (Subscriber+) Arbitrary File Upload

The VikRentCar Car Rental Management System plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.2. This is due to missing or incorrect nonce validation on the 'save' function. This makes…

Versions affectées

*-1.4.2

Correctif

1.4.3

Publication

07/03/2025

CVE-2024-32780 Moyenne · 5,3
VikRentCar Car Rental Management System

VikRentCar Car Rental Management System <= 1.3.2 – Information Exposure

The VikRentCar Car Rental Management System plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.3.2 due to publicly accessible PDF files. This makes it possible for unauthenticated attackers to extract…

Versions affectées

*-1.3.2

Correctif

1.3.3

Publication

22/04/2024

CVE-2023-23998 Moyenne · 5,5
VikRentCar Car Rental Management System

VikRentCar Car Rental Management System <= 1.3.0 – Authenticated (Admin+) Cross Site Scripting

The VikRentCar Car Rental Management System plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.3.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with admin-level…

Versions affectées

*-1.3.0

Correctif

1.3.1

Publication

20/01/2023

CVE-2021-24519 Moyenne · 5,5
VikRentCar Car Rental Management System

VikRentCar Car Rental Management System < 1.1.10 – Authenticated (Admin+) Stored Cross-Site Scripting

The VikRentCar Car Rental Management System WordPress plugin before 1.1.10 does not sanitise the 'Text Next to Icon' field when adding or editing a Characteristic, allowing high privilege users such as admin to use XSS payload in it,…

Versions affectées

[*, 1.1.10)

Correctif

1.1.10

Publication

19/07/2021

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités