Arbitrary File Deletion in Car Dealer Automotive WordPress Theme by ThemeForest
CVE-2025-1282

8.8HIGH

Key Information:

Vendor
Thememakers
Status
Car Dealer Automotive WordPress Theme – Responsive
Vendor
CVE Published:
27 February 2025

Summary

The Car Dealer Automotive WordPress Theme, developed by ThemeForest, is affected by a security vulnerability that allows authenticated users with Subscriber-level access and above to delete arbitrary files on the server. This vulnerability arises from inadequate file path validation within the delete_post_photo() and add_car() functions across all versions up to and including 1.6.3. Attackers could exploit this flaw to potentially remove critical files, such as wp-config.php, which can lead to remote code execution. Additionally, the add_car() function may enable reading of unauthorized files, increasing the risk of further exploitation.

Affected Version(s)

Car Dealer Automotive WordPress Theme – Responsive * <= 1.6.3

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Tonn
.