*It is unclear exactly which version the issue was patched in from the changelog. Therefore, we used the latest version at the time of verification.
Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-54452 | The The Motors - Car Dealer, Rental & Listing WordPress theme theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.6.65. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes. *It is unclear exactly which version the issue was patched in from the changelog. Therefore, we used the latest version at the time of verification. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 06 May 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 03 May 2025 03:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The The Motors - Car Dealer, Rental & Listing WordPress theme theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.6.65. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes. *It is unclear exactly which version the issue was patched in from the changelog. Therefore, we used the latest version at the time of verification. | |
| Title | Motors - Car Dealer, Rental & Listing WordPress theme <= 5.6.65 - Unauthenticated Arbitrary Shortcode Execution | |
| Weaknesses | CWE-94 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2025-05-06T14:34:25.746Z
Reserved: 2025-01-26T19:03:03.326Z
Link: CVE-2024-13738
Updated: 2025-05-06T14:31:02.318Z
Status : Awaiting Analysis
Published: 2025-05-03T03:15:20.013
Modified: 2025-05-05T20:54:19.760
Link: CVE-2024-13738
No data.
OpenCVE Enrichment
No data.
EUVD