CVE-2025-3437: Motors – Car Dealership & Classified Listings Plugin <= 1.4.66 - Missing Authorization to Authenticated (Subscriber+) Wizard Set-up
The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several functions in the ajaxactions.php file in all versions up to, and including, 1.4.66. This makes it possible for authenticated attackers, with Subscriber-level access and above, to execute several initial set-up actions.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3437?
CVE-2025-3437 has a high severity rating due to the potential for unauthorized modification of data.
How do I fix CVE-2025-3437?
To fix CVE-2025-3437, you should update the Motors – Car Dealership & Classified Listings Plugin to version 1.4.67 or later.
What versions are affected by CVE-2025-3437?
CVE-2025-3437 affects all versions of the Motors – Car Dealership & Classified Listings Plugin up to and including version 1.4.66.
What impact does CVE-2025-3437 have on my website?
CVE-2025-3437 can allow unauthorized users to modify data on your website, which can compromise the integrity of your site.
What functions are affected by CVE-2025-3437?
CVE-2025-3437 affects several functions in the ajax_actions.php file due to missing capability checks.