WordPress Plugin CMS für Motorrad Werkstätten Cross-Site Request Forgery Vulnerability

Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the WordPress plugin 'CMS für Motorrad Werkstätten' in versions through 1.0.0. The vulnerability arises from inadequate nonce validation in eight AJAX deletion handlers. This oversight allows unauthenticated attackers to delete various records, including vehicles, contacts, suppliers, receipts, positions, catalog articles, stock items, and entire supplier catalogs, by tricking a logged-in user into interacting with a malicious link or page.

Impact

Exploitation of this vulnerability could lead to unauthorized deletion of critical data, including contacts, suppliers, and various inventory items, potentially disrupting business operations.

Reproduction

To reproduce this vulnerability, an attacker must exploit the missing nonce validation in the AJAX deletion handlers. This can be done by sending a forged request that impersonates a logged-in user, using a method that the application does not properly validate or verify. The absence of nonce checks allows these requests to be processed as if they were legitimate, leading to the unauthorized deletion of the targeted records.

Remediation

No known patch is available. Users are advised to uninstall the affected plugin and seek a replacement.

Added: Apr 17, 2026, 8:29 AM
Updated: Apr 17, 2026, 8:29 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
6.8
remediation
0.0
relevance
6.1
threat
4.8
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.