CVE-2025-2807
Motors – Car Dealership & Classified Listings Plugin <= 1.4.64 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Installation
Severity Score
Exploit Likelihood
Affected Versions
1Public Exploits
1Exploited in Wild
-Decision
Descriptions
The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to arbitrary plugin installations due to a missing capability check in the mvl_setup_wizard_install_plugin() function in all versions up to, and including, 1.4.64. This makes it possible for authenticated attackers, with Subscriber-level access and above, to install and activate arbitrary plugins on the affected site's server which may make remote code execution possible.
El complemento Motors – Car Dealership & Classified Listings Plugin para WordPress es vulnerable a la instalación de complementos arbitrarios debido a una falta de comprobación de capacidad en la función mvl_setup_wizard_install_plugin() en todas las versiones hasta la 1.4.64 incluida. Esto permite que atacantes autenticados, con acceso de suscriptor o superior, instalen y activen complementos arbitrarios en el servidor del sitio afectado, lo que podría posibilitar la ejecución remota de código.
WordPress Motors plugin versions 1.4.64 and below suffer from an arbitrary plugin installation vulnerability.
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2025-03-25 CVE Reserved
- 2025-04-07 CVE Published
- 2025-04-08 CVE Updated
- 2025-04-08 First Exploit
- 2025-04-14 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-862: Missing Authorization
CAPEC
References (3)
URL | Date | SRC |
---|
URL | Date | SRC |
---|