Cross-Site Request Forgery Vulnerability in VikRentCar Plugin for WordPress
CVE-2024-11640
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 8 March 2025
What is CVE-2024-11640?
The VikRentCar Car Rental Management System plugin for WordPress features a vulnerability that allows unauthenticated attackers to exploit missing or incorrect nonce validation in the 'save' function. This weakness enables attackers to manipulate plugin access privileges through crafted requests, potentially tricking site administrators. If an administrator inadvertently performs the action prompted by an attacker, there is a risk that subscribers with adequate privileges could upload arbitrary files on the server, which could facilitate remote code execution.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
VikRentCar Car Rental Management System * <= 1.4.2
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved