Description

The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to arbitrary plugin installations due to a missing capability check in the mvl_setup_wizard_install_plugin() function in all versions up to, and including, 1.4.64. This makes it possible for authenticated attackers, with Subscriber-level access and above, to install and activate arbitrary plugins on the affected site's server which may make remote code execution possible.

INFO

Published Date :

2025-04-08T09:21:18.881Z

Last Modified :

2025-04-08T13:09:19.386Z

Source :

Wordfence
AFFECTED PRODUCTS

The following products are affected by CVE-2025-2807 vulnerability.

Vendors Products
Stylemixthemes
  • Motors - Car Dealer\, Classifieds \& Listing
Wordpress
  • Wordpress

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact