Impact
The WP CarDealer WordPress plugin fails to limit the role that can be assigned during the registration process. This flaw allows anyone, even without logging in, to submit a registration request with the administrator role and thereby obtain full site access. As a result, an attacker could gain complete control over the WordPress installation, read or modify content, change settings, or add malicious plugins.
Affected Systems
The issue affects the ApusTheme WP CarDealer plugin for WordPress. All releases up to and including version 1.2.16 are vulnerable. Sites running any of these versions are susceptible unless a newer, patched version is installed.
Risk and Exploitability
The flaw carries a CVSS score of 9.8, indicating critical severity. The EPSS score is under 1%, showing that exploitation probability is low, and the vulnerability is currently not listed in CISA's KEV. Nonetheless, the unauthenticated nature of the attack vector means anyone can trigger it by forging a registration request. Once exploited, the attacker gains administrator privileges, leading to full compromise of the site.
OpenCVE Enrichment