Motors WordPress Theme Unauthenticated Arbitrary Shortcode Execution Vulnerability

Vulnerability

A vulnerability allowing unauthenticated arbitrary shortcode execution has been identified in the Motors - Car Dealer, Rental & Listing WordPress theme, affecting all versions through 5.6.65. The issue arises because the theme does not properly validate values before executing shortcodes, allowing attackers to execute arbitrary shortcodes on the site.

Impact

Exploitation of this vulnerability allows for arbitrary shortcode execution, which could be used to inject and execute malicious code or actions on the WordPress site.

Remediation

Users are advised to update the Motors WordPress theme to version 5.6.66 or a newer patched version.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
3.4
impact
0.6
exploitability
7.6
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.