Fleetwire Fleet Management Security & Risk Analysis

wordpress.org/plugins/fleetwire-fleet-management

Seamlessly embed Fleetwire to offer online bookings, manage rentals, and sync your car-sharing fleet directly from your WordPress site.

30 active installs v1.0.20 PHP 7.4+ WP 5.0+ Updated Unknown
bookingcalendarfleet-managementrentalvehicle-rentals
99
A · Safe
CVEs total1
Unpatched0
Last CVEJul 22, 2025
Download
Safety Verdict

Is Fleetwire Fleet Management Safe to Use in 2026?

Generally Safe

Score 99/100

Fleetwire Fleet Management has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Jul 22, 2025
Risk Assessment

The fleetwire-fleet-management plugin v1.0.20 exhibits a generally positive security posture based on the static analysis. The absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests is commendable. Furthermore, the plugin successfully utilizes prepared statements for all SQL queries and has a reasonably good output escaping rate. The single AJAX endpoint has a nonce check, which is a positive security measure for handling user input.

However, the plugin is not without potential concerns. The static analysis shows a complete absence of capability checks, meaning that even authenticated users may be able to access or perform actions they shouldn't have permission for. While no critical or high severity taint flows were identified, a significant percentage of outputs are not properly escaped, creating a risk of Cross-Site Scripting (XSS) vulnerabilities. The plugin also has a history of a medium severity CVE related to XSS, indicating a recurring pattern of input sanitization weaknesses.

In conclusion, while fleetwire-fleet-management v1.0.20 demonstrates good practices in many areas, the lack of capability checks and the observed output escaping issues, coupled with past XSS vulnerabilities, represent significant areas for improvement. The plugin has strengths in its handling of database queries and general code hygiene, but these are overshadowed by the potential for privilege escalation and persistent XSS attacks.

Key Concerns

  • No capability checks present
  • 15% of output is unescaped
  • Medium severity CVE history
Vulnerabilities
1

Fleetwire Fleet Management Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-6261medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Fleetwire Fleet Management Plugin <= 1.0.19 - Authenticated (Contributor+) Stored Cross-Site Scripting via fleetwire_list Shortcode

Jul 22, 2025 Patched in 1.0.20 (66d)
Code Analysis
Analyzed Mar 16, 2026

Fleetwire Fleet Management Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
11 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

85% escaped13 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
fleetwire_company_name_form_process (fleetwire.php:30)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Fleetwire Fleet Management Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_fleetwire_company_name_form_processfleetwire.php:451
WordPress Hooks 7
actionadmin_menufleetwire.php:440
actionadmin_noticesfleetwire.php:441
actionadmin_enqueue_scriptsfleetwire.php:442
actionadmin_footerfleetwire.php:443
actionadmin_menufleetwire.php:445
actionwp_enqueue_scriptsfleetwire.php:449
actionwp_headfleetwire.php:450
Maintenance & Trust

Fleetwire Fleet Management Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedUnknown
PHP min version7.4
Downloads4K

Community Trust

Rating0/100
Number of ratings0
Active installs30
Developer Profile

Fleetwire Fleet Management Developer Profile

Fleetwire

1 plugin · 30 total installs

87
trust score
Avg Security Score
99/100
Avg Patch Time
66 days
View full developer profile
Detection Fingerprints

How We Detect Fleetwire Fleet Management

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/fleetwire-fleet-management/assets/fleetwire-admin.css

HTML / DOM Fingerprints

CSS Classes
fleetwire-listing-cardfleetwire-product-buttonfleetwire-product-detailfleetwire-listing-doorsfleetwire-listing-seatsfleetwire-listing-featuresfleetwire-listing-reviewsfleetwire-listing-image-gallery+3 more
Data Attributes
data-iddata-showprice
JS Globals
window.fleetwireOptions
Shortcode Output
<div class="fleetwire-listing-card"<div class="fleetwire-product-button"<div class="fleetwire-product-detail"<span class="fleetwire-listing-doors"
FAQ

Frequently Asked Questions about Fleetwire Fleet Management