Impact
The Car Rental Manager plugin contains a missing authorization flaw that allows requests bypassing the normal WordPress permission checks. This defect can let attackers reach privileged administrative actions or read sensitive booking data without the required capabilities. The weakness is formally identified as improper authorization (CWE-862) and can compromise the confidentiality and integrity of the rental management system.
Affected Systems
The issue affects the WordPress Car Rental Manager plugin, released by MagePeopleTeam, in all versions from the initial release up through 1.0.9. Any WordPress site with an installation of the plugin at or below version 1.0.9 is vulnerable.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate severity. The EPSS score is below 1%, which suggests the likelihood of exploitation at this time is low, and the vulnerability is not listed in CISA’s KEV catalog. Attackers would need to target a WordPress site that has the vulnerable plugin installed; successful exploitation would likely grant unauthorized access to administrative functions or sensitive rental data rather than full remote code execution.
OpenCVE Enrichment