CarDealer
cpe:2.3:a:car_dealer_project:car_dealer:*:*:*:*:wordpress:*:*
- <= 1.6.4
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the Cardealer theme for WordPress, affecting versions through 1.6.4. The issue arises from inadequate nonce validation in the 'update_user_profile' function, allowing unauthenticated attackers to manipulate user email and password by sending forged requests. This exploitation requires tricking a site administrator into performing a specific action, such as clicking a link.
Exploitation of this vulnerability allows for unauthorized changes to user email and password, potentially leading to account takeover.
Users are advised to update to version 1.6.5 or a later patched version.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.