Motors WordPress Plugin Shortcode Execution Vulnerability

Vulnerability

A vulnerability exists in the Motors – Car Dealer, Classifieds & Listing plugin for WordPress, allowing authenticated users with Subscriber-level access and above to execute arbitrary shortcodes. This issue is present in all versions through 1.4.43. The vulnerability arises because the plugin does not properly validate user input before processing shortcodes, enabling the execution of potentially harmful code.

Impact

Exploitation of this vulnerability could lead to unauthorized shortcode execution, which may allow attackers to inject and execute malicious code or actions within the WordPress site.

Remediation

Users are advised to update the Motors – Car Dealer, Classifieds & Listing plugin to version 1.4.44 or a newer patched version.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
3.4
impact
1.3
exploitability
6.1
remediation
7.7
relevance
0.0
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.