WebTemplateMasters CarDealer
cpe:2.3:a:car_dealer_/_auto_dealer_responsive_project:car_dealer_/_auto_dealer_responsive:*:*:*:*:wordpress:*:*
- <= 1.6.4
A vulnerability exists in the Cardealer theme for WordPress, specifically in versions through 1.6.4. The issue arises from a lack of proper capability checks and filename sanitization in the demo theme scheme AJAX functions. This vulnerability enables authenticated attackers with subscriber-level access and above to unauthorizedly modify or delete arbitrary CSS and JavaScript files, leading to potential data loss and unauthorized data changes.
Exploitation of this vulnerability could result in unauthorized modification or deletion of CSS and JavaScript files, allowing for potential data loss or disruption of site functionality.
Users are advised to update the Cardealer theme to version 1.6.5 or a newer patched version.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.