Cross-Site Request Forgery Vulnerability in VikRentCar Plugin for WordPress
CVE-2024-11640
8.8HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 8 March 2025
What is CVE-2024-11640?
The VikRentCar Car Rental Management System plugin for WordPress features a vulnerability that allows unauthenticated attackers to exploit missing or incorrect nonce validation in the 'save' function. This weakness enables attackers to manipulate plugin access privileges through crafted requests, potentially tricking site administrators. If an administrator inadvertently performs the action prompted by an attacker, there is a risk that subscribers with adequate privileges could upload arbitrary files on the server, which could facilitate remote code execution.
Affected Version(s)
VikRentCar Car Rental Management System * <= 1.4.2