CVE-2024-10970: Motors – Car Dealer, Classifieds & Listing <= 1.4.43 - Authenticated (Subscriber+) Arbitrary Shortcode Execution via Custom Title
The The Motors – Car Dealer, Classifieds & Listing plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.4.43. This is due to the software allowing users to execute an action that does not properly validate a value before running doshortcode. This makes it possible for authenticated attackers, with Subscriber-level access and above, to execute arbitrary shortcodes.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-10970?
CVE-2024-10970 is classified as a high severity vulnerability due to its potential to execute arbitrary shortcodes.
How do I fix CVE-2024-10970?
To fix CVE-2024-10970, update the Motors – Car Dealer, Classifieds & Listing plugin to version 1.4.44 or later.
What versions of the Motors plugin are affected by CVE-2024-10970?
All versions of the Motors – Car Dealer, Classifieds & Listing plugin up to and including version 1.4.43 are affected by CVE-2024-10970.
What is the impact of exploiting CVE-2024-10970?
Exploiting CVE-2024-10970 can allow attackers to execute arbitrary PHP code, potentially compromising the WordPress site.
Who should be concerned about CVE-2024-10970?
All users and administrators of the Motors – Car Dealer, Classifieds & Listing plugin who have not updated to version 1.4.44 or later should be concerned about CVE-2024-10970.