CVE-2025-10494: Motors – Car Dealership & Classified Listings Plugin <= 1.4.89 - Authenticated (Subscriber+) Arbitrary File Deletion
The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation when deleting profile pictures in all versions up to, and including, 1.4.89. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-10494?
CVE-2025-10494 is considered a critical vulnerability due to its ability to allow arbitrary file deletion.
How do I fix CVE-2025-10494?
To fix CVE-2025-10494, update the Motors – Car Dealership & Classified Listings Plugin to version 1.4.90 or higher.
Which versions are affected by CVE-2025-10494?
CVE-2025-10494 affects all versions of the Motors – Car Dealership & Classified Listings Plugin up to and including version 1.4.89.
Who is at risk with CVE-2025-10494?
Authenticated users of the Motors – Car Dealership & Classified Listings Plugin are at risk with CVE-2025-10494.
What type of vulnerability is CVE-2025-10494?
CVE-2025-10494 is an arbitrary file deletion vulnerability due to insufficient file path validation.