CVE-2024-39653 CRITICAL

CVE-2024-39653: WordPress VikRentCar Car Rental Management System plugin <= 1.4.0 - SQL Injection vulnerability

Vendor E4J S.r.l.
Product VikRentCar
Weakness CWE-89 · SQLi
Published August 29, 2024
Last update April 28, 2026

CVSS base score

9.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality High
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L

What the vulnerability does

01Description

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in E4J s.R.L. VikRentCar allows SQL Injection.This issue affects VikRentCar: from n/a through 1.4.0.

Explanation of Vulnerability in Simple Terms

02Summary

VikRentCar versions up to 1.4.0 contain a SQL injection vulnerability in an unauthenticated network-accessible component. An attacker can craft malicious input to extract sensitive data from the database, including user credentials and rental information. The vulnerability requires no authentication or user interaction. Update to version 1.4.6 or later to remediate.

What an attacker can do

03Attacker Capabilities

Extract sensitive data from the database, including user credentials and rental records.

Potential impact on your site

04Site Impact

Rental customer data, user credentials, and business information can be stolen without warning or authentication.

Conditions required to exploit

05Prerequisites

Network access to the VikRentCar installation; no authentication required.

Key dates

06Disclosure timeline

August 29, 2024 CVE published
April 28, 2026 Record updated

Related vulnerabilities

08Related CVE