Junglewise Threat Intelligence

CVE-2026-39687: Rapid Car Check Vehicle Data missing authorization in WordPress plugin

CVE-2026-39687 · Severity: medium · CVSS 5.3 · Published 2026-04-08

Executive brief

The Rapid Car Check Vehicle Data plugin for WordPress, which provides UK vehicle information, contains a security flaw in its access control settings. This vulnerability allows unauthorized individuals to bypass intended security levels and potentially perform actions or access data they should not be able to. While the impact is considered moderate, it could lead to unauthorized modifications or service disruptions on affected websites.

Technical details

A Missing Authorization (CWE-862) vulnerability exists in the Rapid Car Check Vehicle Data plugin (free-vehicle-data-uk) for WordPress through version 2.1.2. The flaw stems from a failure to properly validate user permissions or implement sufficient nonce/authentication checks on certain functions. An unauthenticated remote attacker can exploit this to bypass security levels and execute actions that should be restricted to higher-privileged users. The vulnerability is resolved in version 2.1.3.

Affected products

  • Rapid Car Check Rapid Car Check Vehicle Data (free-vehicle-data-uk) <= 2.1.2

Timeline

  • 2026-01-24: other: Reported by Legion Hunter
  • 2026-02-23: disclosed: Initial disclosure by Patchstack
  • 2026-02-23: patched: Version 2.1.3 released to address the vulnerability
  • 2026-04-08: advisory: CVE-2026-39687 published

References