Impact
The vulnerability is a missing authorization flaw in the Car Rental Manager plugin for WordPress, allowing attackers to exploit incorrectly configured access control security levels. An attacker who can reach the plugin’s functions could gain access to privileged actions or sensitive data that should be protected by role‑based restrictions. The weakness is identified as CWE‑862.
Affected Systems
The Car Rental Manager plugin developed by magepeopleteam, from n/a through version 1.3.7, is affected.
Risk and Exploitability
The CVSS score of 5.3 indicates medium severity, while an EPSS score of less than 1% suggests a low likelihood of widespread exploitation. This issue is not listed in CISA’s KEV catalog. Based on the nature of the missing authorization flaw, the likely attack vector is the plugin’s administrative or API endpoints, which can be accessed from the internet. An unauthenticated user or a user with a compromised account could potentially misuse the plugin’s functionality due to the lack of proper access checks.
OpenCVE Enrichment