WordPress · The Motors – Car Dealer · CVE-2024-10970
**Name of the Vulnerable Software and Affected Versions**
The Motors – Car Dealer, Classifieds & Listing plugin for WordPress versions 1.4.43 and earlier
**Description**
The issue allows authenticated attackers with Subscriber-level access and above to execute arbitrary shortcodes due to the software permitting users to execute an action without properly validating a value before running `do shortcode`. This enables the execution of arbitrary shortcodes.
**Recommendations**
For versions 1.4.43 and earlier, update to a version later than 1.4.43 to resolve the issue. As a temporary workaround, consider restricting access to the `do shortcode` function to minimize the risk of exploitation.