The CarSpot – Dealership Wordpress Classified Theme theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 2.4.3. This is due to the plugin not properly validating a token prior to updating a user's password. This makes it possible for unauthenticated attackers to change arbitrary user's passwords, including administrators, and leverage that to gain access to their account.
Metrics
Affected Vendors & Products
References
History
Fri, 21 Feb 2025 16:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Carspot Project
Carspot Project carspot |
|
Weaknesses | NVD-CWE-noinfo | |
CPEs | cpe:2.3:a:carspot_project:carspot:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Carspot Project
Carspot Project carspot |
Tue, 18 Feb 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 18 Feb 2025 08:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The CarSpot – Dealership Wordpress Classified Theme theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 2.4.3. This is due to the plugin not properly validating a token prior to updating a user's password. This makes it possible for unauthenticated attackers to change arbitrary user's passwords, including administrators, and leverage that to gain access to their account. | |
Title | CarSpot – Dealership Wordpress Classified Theme <= 2.4.3 - Unauthenticated Arbitrary Password Reset/Account Takeover | |
Weaknesses | CWE-620 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2025-02-18T14:33:14.791Z
Reserved: 2024-12-20T17:00:35.574Z
Link: CVE-2024-12860

Updated: 2025-02-18T14:33:08.579Z

Status : Analyzed
Published: 2025-02-18T09:15:08.660
Modified: 2025-02-21T15:30:47.383
Link: CVE-2024-12860

No data.