Lucene search

K
patchstackSatyender YadavPATCHSTACK:0F3D0B977E0D5647DA858E4D6ACB6DA9
HistoryJun 14, 2021 - 12:00 a.m.

WordPress VikRentCar plugin <= 1.1.6 - Cross-Site Request Forgery (CSRF) vulnerability leading to Stored Cross-Site Scripting (XSS)

2021-06-1400:00:00
Satyender Yadav
patchstack.com
5

0.001 Low

EPSS

Percentile

21.2%

Cross-Site Request Forgery (CSRF) vulnerability leading to Stored Cross-Site Scripting (XSS) discovered by Satyender Yadav in WordPress VikRentCar plugin (versions <= 1.1.6).

Solution

           Update the WordPress VikRentCar plugin to the latest available version (at least 1.1.7).
CPENameOperatorVersion
vikrentcarle1.1.6

0.001 Low

EPSS

Percentile

21.2%

Related for PATCHSTACK:0F3D0B977E0D5647DA858E4D6ACB6DA9