PT-2026-102304 · WordPress · Wp Vehicle Manager
CVSS v4.0
9.3
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Vehicle Manager (Free) versions prior to 6.5.8
Description
An unauthenticated SQL Injection exists in the
site/vehiclemanager.php file. The issue occurs because the order field and order direction parameters are processed through a sanitizing function that applies escaping, but the resulting values are placed into an unquoted ORDER BY clause, rendering the escaping ineffective. This flaw is reachable via three anonymous frontend entry points: category listing, search, and the all-vehicles listing.Recommendations
Update Vehicle Manager (Free) to version 6.5.8 or later.
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wp Vehicle Manager