Impact
The plugin contains a missing authorization check (CWE-862) in the mvl_ajax_dealer_load_cars() function, allowing anyone to retrieve private or draft car listings. The vulnerability exposes the contents of listings that are intended to be confidential, thereby compromising confidentiality for the affected users and potentially revealing sensitive information to attackers.
Affected Systems
WordPress sites that use the Motors – Car Dealership & Classified Listings plugin, stylemix, all versions up to (and including) 1.4.120.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate risk, and the EPSS score of less than 1% suggests a low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. An unauthenticated attacker can exploit the flaw simply by sending a request to the plugin’s AJAX endpoint over the network, with no prerequisites beyond access to the site’s URL. If exploited, the attacker can read private or draft listings and potentially gather personal or proprietary data.
OpenCVE Enrichment