Arbitrary Shortcode Execution Vulnerability in Motors WordPress Theme
CVE-2024-13738

7.3HIGH

What is CVE-2024-13738?

The Motors - Car Dealer, Rental & Listing WordPress theme is susceptible to an arbitrary shortcode execution vulnerability that affects all versions up to and including 5.6.65. This flaw allows unauthenticated attackers to execute arbitrary shortcodes due to improper validation of values before executing the do_shortcode function. This poses a significant risk to users of the theme, as it can lead to unauthorized actions being performed on the site. Users are strongly encouraged to update to the latest version to mitigate this risk.

Affected Version(s)

Motors - Car Dealer, Rental & Listing WordPress theme * <= 5.6.65

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Lucio Sá
.