Impact
The vulnerability allows PHP object injection within the Car Rental Manager plugin up to version 1.3.9. This weakness can be exploited to execute arbitrary PHP code in the context of the WordPress site, potentially compromising all data and the integrity of the server. The injection flaw stems from insecure handling of serialized objects, classified as CWE-502.
Affected Systems
The affected product is the Car Rental Manager plugin developed by MagePeopleTeam, version 1.3.9 and earlier. The plugin is hosted on WordPress sites that have installed it.
Risk and Exploitability
The CVSS score of 7.2 indicates a high severity. While the EPSS score is not available, the lack of listing in the CISA KEV catalog suggests that mass exploitation has not yet been observed. The likely attack vector requires access to the plugin’s editor interface, which typically means the attacker must be authenticated with sufficient privileges, but successful exploitation leads to full remote code execution.
OpenCVE Enrichment