Motors Car Dealer & Classified Ads <= 1.4.0 - Unauthenticated Settings Import/Export
2019-09-20 00:00
Jerome BruandetStrategic Overview
StatusPatched in 1.4.1
Affected PluginMotors – Car Dealership & Classified Listings Plugin
Affected Version
< 1.4.1CVSS6.5Medium
CVE
CVE-2019-17228Vulnerability Overview
includes/options.php in the motors-car-dealership-classified-listings (aka Motors - Car Dealer & Classified Ads) plugin through 1.4.0 for WordPress allows unauthenticated plugin settings changes, including the ability to add malicious JavaScript to a site.
Technical Analysis
REMEDIATION: Update to version 1.4.1, or a newer patched version --- IDENTIFIER: CWE-345 (Insufficient Verification of Data Authenticity) The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C