CVE-2024-13737: Motors – Car Dealer, Classifieds & Listing <= 1.4.57 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Deletion and Listing Template Creation
The Motors – Car Dealer, Classifieds & Listing plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability checks on the motorscreatetemplate and motorsdeletetemplate functions in all versions up to, and including, 1.4.57. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary posts or create listing templates. This issue requires Elementor plugin to be installed, which is a required plugin for Motors Starter Theme.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-13737?
CVE-2024-13737 has a medium severity rating due to potential unauthorized data modifications.
How do I fix CVE-2024-13737?
To fix CVE-2024-13737, update the Motors – Car Dealer, Classifieds & Listing plugin to version 1.4.58 or later.
What functions are affected by CVE-2024-13737?
CVE-2024-13737 affects the motors_create_template and motors_delete_template functions.
Which versions of the Motors plugin are vulnerable to CVE-2024-13737?
All versions of the Motors – Car Dealer, Classifieds & Listing plugin up to and including version 1.4.57 are vulnerable to CVE-2024-13737.
What type of vulnerability is CVE-2024-13737 classified as?
CVE-2024-13737 is classified as an unauthorized modification of data vulnerability.