PT-2026-95133 · WordPress · Motors – Car Dealership & Classified Listings Plugin
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
The Motors – Car Dealership & Classified Listings Plugin versions prior to 1.4.121
Description
Missing authorization checks in the
mvl ajax dealer load cars() function allow unauthenticated attackers to gain unauthorized access to data. This flaw enables the retrieval of draft, pending, private, and future car listings belonging to arbitrary users.Recommendations
Update the plugin to a version later than 1.4.120.
As a temporary workaround, consider restricting access to the
mvl ajax dealer load cars() function until the update is applied.Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Motors – Car Dealership & Classified Listings Plugin