Description
Editor PHP Object Injection in Car Rental Manager <= 1.3.9 versions.
Published: 2026-08-13
Score: 7.2 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows PHP object injection within the Car Rental Manager plugin up to version 1.3.9. This weakness can be exploited to execute arbitrary PHP code in the context of the WordPress site, potentially compromising all data and the integrity of the server. The injection flaw stems from insecure handling of serialized objects, classified as CWE-502.

Affected Systems

The affected product is the Car Rental Manager plugin developed by MagePeopleTeam, version 1.3.9 and earlier. The plugin is hosted on WordPress sites that have installed it.

Risk and Exploitability

The CVSS score of 7.2 indicates a high severity. While the EPSS score is not available, the lack of listing in the CISA KEV catalog suggests that mass exploitation has not yet been observed. The likely attack vector requires access to the plugin’s editor interface, which typically means the attacker must be authenticated with sufficient privileges, but successful exploitation leads to full remote code execution.

Generated by OpenCVE AI on August 13, 2026 at 15:25 UTC.

Remediation

Vendor Solution

Update the WordPress Car Rental Manager plugin to the latest available version (at least 1.4.0).


OpenCVE Recommended Actions

  • Update the WordPress Car Rental Manager plugin to version 1.4.0 or newer.
  • Disable or remove the Car Rental Manager plugin if it is not essential to operations.
  • Limit access to the plugin’s editor feature by providing only the minimum necessary WordPress roles to users who need it.

Generated by OpenCVE AI on August 13, 2026 at 15:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Magepeopleteam
Magepeopleteam car Rental Manager
Wordpress
Wordpress wordpress
Vendors & Products Magepeopleteam
Magepeopleteam car Rental Manager
Wordpress
Wordpress wordpress

Thu, 13 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
Description Editor PHP Object Injection in Car Rental Manager <= 1.3.9 versions.
Title WordPress Car Rental Manager plugin <= 1.3.9 - PHP Object Injection vulnerability
Weaknesses CWE-502
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Magepeopleteam Car Rental Manager
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-13T15:13:43.676Z

Reserved: 2026-02-19T09:51:58.586Z

Link: CVE-2026-27380

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-13T14:16:55.987

Modified: 2026-08-13T14:16:55.987

Link: CVE-2026-27380

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T15:30:04Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data