Impact
The vulnerability is an unauthenticated cross‑site scripting flaw found in VikRentCar plugin versions up to 1.4.6. Attackers can inject malicious scripts that are executed in the browsers of site visitors, potentially allowing data theft, session hijacking, or defacement. This is a CWE‑79 type flaw.
Affected Systems
The affected system is the WordPress plugin VikRentCar by e4jvikwp, specifically all releases with a version number of 1.4.6 or earlier. Users running these versions are vulnerable, regardless of authentication level, as the flaw is exploitable without credentials.
Risk and Exploitability
The CVSS score for this issue is 7.1, indicating a moderate severity. The EPSS score is not available, so the likelihood of exploitation is unclear, but the lack of an existing KEV listing suggests no confirmed widespread attacks yet. The attacker can execute the exploit through the web interface that accepts user input, so sites that expose the plugin publicly are at risk.
OpenCVE Enrichment