Junglewise Threat Intelligence

CVE-2026-61985: magepeopleteam Car Rental Manager missing authorization

CVE-2026-61985 · Severity: medium · CVSS 5.3 · Published 2026-07-13

Vendors: MagePeople Team.

Executive brief

The Car Rental Manager plugin for WordPress, which manages vehicle bookings and rental operations, contains a security flaw in its access control system. An unauthorized user can exploit incorrectly configured security levels to perform actions they should not be allowed to do. This could lead to unauthorized modifications of rental data or system settings, potentially disrupting business operations.

Technical details

A Missing Authorization vulnerability (CWE-862) exists in the magepeopleteam Car Rental Manager plugin for WordPress through version 1.3.7. The flaw stems from incorrectly configured access control security levels within the plugin's components. A remote, unauthenticated attacker can exploit this weakness via the network to perform unauthorized actions. According to the CVSS metrics, the primary impact is on integrity, allowing for unauthorized data modification without affecting confidentiality or availability. The issue is addressed in version 1.3.8.

Affected products

  • magepeopleteam Car Rental Manager <= 1.3.7

Timeline

  • 2026-07-13: disclosed
  • 2026-07-13: advisory
  • 1.3.8: patched: Fixed in version 1.3.8

References