Arbitrary File Deletion in Car Dealer Automotive WordPress Theme by ThemeForest
CVE-2025-1282
Key Information:
- Vendor
- Thememakers
- Status
- Car Dealer Automotive WordPress Theme – Responsive
- Vendor
- CVE Published:
- 27 February 2025
Summary
The Car Dealer Automotive WordPress Theme, developed by ThemeForest, is affected by a security vulnerability that allows authenticated users with Subscriber-level access and above to delete arbitrary files on the server. This vulnerability arises from inadequate file path validation within the delete_post_photo() and add_car() functions across all versions up to and including 1.6.3. Attackers could exploit this flaw to potentially remove critical files, such as wp-config.php, which can lead to remote code execution. Additionally, the add_car() function may enable reading of unauthorized files, increasing the risk of further exploitation.
Affected Version(s)
Car Dealer Automotive WordPress Theme – Responsive * <= 1.6.3
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved