PT-2025-27838 · WordPress · Vikrentcar Car Rental Management System

Published

2025-07-03

·

Updated

2025-07-06

·

CVE-2025-5322

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: VikRentCar Car Rental Management System plugin for WordPress versions up to, and including, 1.4.3
Description: The issue is related to missing file type validation in the do updatecar and createcar functions, allowing authenticated attackers with Administrator-level access and above to upload arbitrary files on the affected site's server. This may make remote code execution possible.
Recommendations: For versions up to, and including, 1.4.3, update to a version that includes the fix for the missing file type validation in the do updatecar and createcar functions. As a temporary workaround, consider disabling the do updatecar and createcar functions until a patch is available. Restrict access to the VikRentCar Car Rental Management System plugin to minimize the risk of exploitation.

Fix

RCE

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2025-5322

Affected Products

Vikrentcar Car Rental Management System