CVE-2025-2807
CVSS 3.1 Score 8.8 of 10 (high)
Details
Published Apr 8, 2025
CWE ID 862
Summary
CVE-2025-2807 is a vulnerability affecting the Motors – Car Dealership & Classified Listings Plugin for WordPress. This issue arises from a missing capability check in the mvl_setup_wizard_install_plugin() function, which exists in all versions up to and including 1.4.64. As a result, authenticated attackers with Subscriber-level access or higher can install and activate arbitrary plugins on the affected site's server, potentially leading to remote code execution risks.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.