Cross-Site Request Forgery Vulnerability in VikRentCar Plugin for WordPress
CVE-2024-11640

8.8HIGH

What is CVE-2024-11640?

The VikRentCar Car Rental Management System plugin for WordPress features a vulnerability that allows unauthenticated attackers to exploit missing or incorrect nonce validation in the 'save' function. This weakness enables attackers to manipulate plugin access privileges through crafted requests, potentially tricking site administrators. If an administrator inadvertently performs the action prompted by an attacker, there is a risk that subscribers with adequate privileges could upload arbitrary files on the server, which could facilitate remote code execution.

Affected Version(s)

VikRentCar Car Rental Management System * <= 1.4.2

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Noah Stead
.