Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-5545


The Motors – Car Dealer, Classifieds & Listing plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the stm_edit_delete_user_car function in all versions up to, and including, 1.4.8. This makes it possible for unauthenticated attackers to unpublish arbitrary posts and pages.


Published

2024-07-02T08:15:07.190

Last Modified

2024-11-21T09:47:53.940

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.3 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-862

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application stylemixthemes motors_-_car_dealer\,_classifieds_\&_listing < 1.4.11 Yes

References