Cross-Site Request Forgery Vulnerability in VikRentCar Plugin for WordPress
CVE-2024-11640
8.8HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 8 March 2025
What is CVE-2024-11640?
The VikRentCar Car Rental Management System plugin for WordPress features a vulnerability that allows unauthenticated attackers to exploit missing or incorrect nonce validation in the 'save' function. This weakness enables attackers to manipulate plugin access privileges through crafted requests, potentially tricking site administrators. If an administrator inadvertently performs the action prompted by an attacker, there is a risk that subscribers with adequate privileges could upload arbitrary files on the server, which could facilitate remote code execution.
Affected Version(s)
VikRentCar Car Rental Management System * <= 1.4.2
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Noah Stead