vipdrv

vipdrv has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it remains unpatched as of September 2026. Their average CVSS score is 4.4, and the most serious one scores 4.4 out of 10.

The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).

The one issue recorded for vipdrv has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2025.

All of these findings were reported by Vinit Lakra. The current release is tested up to WordPress 4.9.31.

Strategic Overview

Avg CVSSMedium
4.4/ 10
Patch Coverage0%
Open

1

Fixed

0

Get automatic notifications for all vipdrv vulnerabilities before they are exploited.

Most severe open issueCVSS 4.4CVE-2025-58884

vipdrv <= 1.0.3 - Authenticated (Administrator+) Stored Cross-Site Scripting

Read the full analysis

Vulnerability Records

1 records
vipdrv banner
Latestv1.0.3
0.0(0)
0/100
Last Updated
2018-02-14 (9y ago)
Active Installs
0+
Downloads
1,536
Requires WP
3.0.1+
Requires PHP
5.2.4+
Tested up to
WP 4.9.31
Created
2018-02-01 (9y ago)

Add the VIPdrv WordPress Plugin to your dealer website and generate more test drive appointments. VIPdrv increases test drive leads, while creating the best online customer experience, which drives to the best dealership visit and sales of a car. VIPdrv resides on your dealership website VDPs and SRPs. We provide you with custom buttons (CTAs) to place on your vehicle detail pages and search result pages. Our custom VIPdrv button drives attention, creating more test drive opportunities for your dealership. Developer Notes: When you activate the VIPdrv WordPress Plugin (widget) it will load a remote script from https://widget.testdrive.pw/integration/integration.js and appends it to the footer of your web page. During initialization process widget will load the details of your website and VIPdrv account created at http://admin.testdrive.pw over HTTP requests from https://api.testdrive.pw When a test drive appointment has been booked, widget will send another HTTP requests to https://api.testdrive.pw to notify you about a new lead. More information about VIPdrv can be found at https://www.vipdrv.com Arbitrary section

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C