PT-2026-102304 · WordPress · Wp Vehicle Manager

·

CVE-2026-101108

·

Published

2026-09-28

·

Updated

2026-09-30

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Vehicle Manager (Free) versions prior to 6.5.8
Description An unauthenticated SQL Injection exists in the site/vehiclemanager.php file. The issue occurs because the order field and order direction parameters are processed through a sanitizing function that applies escaping, but the resulting values are placed into an unquoted ORDER BY clause, rendering the escaping ineffective. This flaw is reachable via three anonymous frontend entry points: category listing, search, and the all-vehicles listing.
Recommendations Update Vehicle Manager (Free) to version 6.5.8 or later.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-101108

Affected Products

Wp Vehicle Manager