The VikRentCar Car Rental Management System plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'month' parameter in all versions up to, and including, 1.4.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Metrics
Affected Vendors & Products
References
History
Thu, 04 Dec 2025 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
E4j
E4j vikrentcar Car Rental Management System Wordpress Wordpress wordpress |
|
| Vendors & Products |
E4j
E4j vikrentcar Car Rental Management System Wordpress Wordpress wordpress |
Tue, 02 Dec 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 02 Dec 2025 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The VikRentCar Car Rental Management System plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'month' parameter in all versions up to, and including, 1.4.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. | |
| Title | VikRentCar Car Rental Management System <= 1.4.4 - Authenticated (Author+) SQL Injection via 'month' Parameter | |
| Weaknesses | CWE-89 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published: 2025-12-02T08:24:54.360Z
Updated: 2025-12-02T14:41:38.713Z
Reserved: 2025-11-25T22:27:24.607Z
Link: CVE-2025-13724
Updated: 2025-12-02T14:41:35.768Z
Status : Awaiting Analysis
Published: 2025-12-02T09:15:47.563
Modified: 2025-12-02T17:16:29.163
Link: CVE-2025-13724
No data.