CVE-2025-2807: Motors – Car Dealership & Classified Listings Plugin <= 1.4.64 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Installation
The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to arbitrary plugin installations due to a missing capability check in the mvlsetupwizardinstallplugin() function in all versions up to, and including, 1.4.64. This makes it possible for authenticated attackers, with Subscriber-level access and above, to install and activate arbitrary plugins on the affected site's server which may make remote code execution possible.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-2807?
CVE-2025-2807 is rated as a high-severity vulnerability due to its potential for arbitrary plugin installations.
How do I fix CVE-2025-2807?
To fix CVE-2025-2807, update the Motors Car Dealership & Classified Listings Plugin to version 1.4.65 or later.
What systems are affected by CVE-2025-2807?
CVE-2025-2807 affects all versions of the Motors Car Dealership & Classified Listings Plugin up to and including version 1.4.64.
What type of vulnerability is CVE-2025-2807?
CVE-2025-2807 is classified as a vulnerability allowing arbitrary code execution due to a missing capability check.
Who should be concerned about CVE-2025-2807?
Website administrators using the Motors Car Dealership & Classified Listings Plugin should be particularly concerned about CVE-2025-2807.