Impact
The vulnerability is a broken access control flaw in the WordPress Motors plugin, affecting all releases before 1.4.107. It allows a user with subscriber-level privileges to carry out actions reserved for higher‑privileged roles, such as editing or deleting listings. The impact is unauthorized access to data and potential modification of vehicle listings, compromising the integrity of the application. This flaw is classified as CWE‑862.
Affected Systems
This issue affects the StylemixThemes Motors plugin for WordPress before version 1.4.107. Any WordPress site that has installed Motors in a vulnerable version is potentially exposed.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. The EPSS score of less than 1% shows a very low probability of exploitation at this time, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack path involves a subscriber account that an attacker can create or compromise to gain unauthorized access. Once authenticated, the attacker can perform privileged actions within the plugin, leading to unauthorized access or data modification.
OpenCVE Enrichment