Junglewise Threat Intelligence

CVE-2026-52699: VikWP VikRentCar IDOR in WordPress plugin

CVE-2026-52699 · Severity: high · CVSS 7.5 · Published 2026-06-15

Executive brief

VikRentCar, a popular car rental management plugin for WordPress, contains a security flaw that allows unauthorized individuals to access sensitive information. By manipulating web requests, an attacker can view data they are not permitted to see, such as customer or booking details, without needing to log in. This could lead to a significant data breach and compromise customer privacy.

Technical details

An Insecure Direct Object Reference (IDOR) vulnerability exists in the VikRentCar plugin for WordPress through version 1.4.5. The flaw is categorized as CWE-639, where the application fails to perform adequate authorization checks when a user-controlled key is used to access a database object. An unauthenticated remote attacker can exploit this by modifying parameters in a request to access sensitive records or files belonging to other users or the system. The vulnerability is resolved in version 1.4.6.

Affected products

  • VikWP VikRentCar <= 1.4.5

Timeline

  • 2026-05-10: other: Reported by researcher dodoh4t
  • 2026-06-10: patched: Version 1.4.6 released
  • 2026-06-15: disclosed: NVD publication date

References