- Description
- The CarSpot – Dealership Wordpress Classified Theme theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 2.4.3. This is due to the plugin not properly validating a token prior to updating a user's password. This makes it possible for unauthenticated attackers to change arbitrary user's passwords, including administrators, and leverage that to gain access to their account.
- Source
- security@wordfence.com
- NVD status
- Analyzed
CVSS 3.1
- Type
- Primary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
- security@wordfence.com
- CWE-620
- nvd@nist.gov
- NVD-CWE-noinfo
- Hype score
- Not currently trending
CVE-2024-12860 (CVSS:9.8, CRITICAL) is Analyzed. The CarSpot – Dealership Wordpress Classified Theme theme for WordPress is vulnerable to privilege escalation via accoun..https://t.co/wtYukJCSrq #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre
@cracbot
23 Feb 2025
3 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 Critical Security Vulnerability 🆔 CVE-2024-12860 💣 CVSS Score: 9.8 📅 Published Date: 25/02/18 ⚠️ Details: The CarSpot – Dealership Wordpress Classified Theme theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including,
@DarkWebInformer
18 Feb 2025
2179 Impressions
2 Retweets
11 Likes
5 Bookmarks
0 Replies
0 Quotes
CVE-2024-12860 The CarSpot – Dealership Wordpress Classified Theme theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and includin… https://t.co/X1dQqx7dUv
@CVEnew
18 Feb 2025
363 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[CVE-2024-12860: CRITICAL] WordPress theme CarSpot - Dealership Classified is at risk! Versions up to 2.4.3 suffer from privilege escalation allowing takeover due to unchecked token validation during password upd...#cybersecurity,#vulnerability https://t.co/Uuk415JLRv https://t.c
@CveFindCom
18 Feb 2025
27 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:carspot_project:carspot:*:*:*:*:*:wordpress:*:*",
"vulnerable": true,
"matchCriteriaId": "7FBDA1A0-9DC8-4361-8EFC-AD99A9D2ECBE",
"versionEndExcluding": "2.4.4"
}
],
"operator": "OR"
}
]
}
]