Motors Car Dealership and Classified Listings Plugin Missing Authorization Vulnerability Allowing Arbitrary Plugin Installation

Vulnerability

A vulnerability exists in the Motors – Car Dealership & Classified Listings Plugin for WordPress, in all versions through 1.4.64. The issue arises from a missing capability check in the 'mvl_setup_wizard_install_plugin()' function, which allows authenticated users with Subscriber-level access and above to install and activate arbitrary plugins on the affected site's server. This could potentially lead to remote code execution.

Impact

Exploitation of this vulnerability could allow authenticated users with Subscriber-level access and above to install and activate malicious plugins, potentially leading to remote code execution on the affected site.

Remediation

Users are advised to update the plugin to version 1.4.65 or a newer patched version.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
5.9
remediation
7.7
relevance
0.0
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.