PT-2025-48656 · WordPress · Vikrentcar Car Rental Management System

Zhenhua Fan

·

Published

2025-12-02

·

Updated

2025-12-02

·

CVE-2025-13724

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions VikRentCar Car Rental Management System plugin for WordPress versions through 1.4.4
Description The VikRentCar Car Rental Management System plugin for WordPress is susceptible to time-based blind SQL Injection. This is due to inadequate escaping of user-supplied input and insufficient preparation of existing SQL queries, specifically through the month parameter. Authenticated attackers with Administrator-level access or higher can append SQL queries to existing ones, potentially extracting sensitive information from the database.
Recommendations Update the VikRentCar Car Rental Management System plugin to a version later than 1.4.4.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-13724

Affected Products

Vikrentcar Car Rental Management System