First published: Tue Jul 02 2024(Updated: )
The Motors – Car Dealer, Classifieds & Listing plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the stm_edit_delete_user_car function in all versions up to, and including, 1.4.8. This makes it possible for unauthenticated attackers to unpublish arbitrary posts and pages.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
Stylemixthemes Motors - Car Dealer, Classifieds & Listing | <1.4.11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-5545 is considered a high severity vulnerability due to the potential for unauthorized data modification.
To fix CVE-2024-5545, update the Motors – Car Dealer, Classifieds & Listing plugin to version 1.4.9 or higher.
CVE-2024-5545 affects all versions of the Motors – Car Dealer, Classifieds & Listing plugin for WordPress up to and including version 1.4.8.
The stm_edit_delete_user_car function is vulnerable in CVE-2024-5545 due to a missing capability check.
Yes, CVE-2024-5545 can be exploited by unauthenticated users, allowing them to modify data without authorization.