CVE-2024-12860
The CarSpot – Dealership Wordpress Classified Theme theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 2.4.3. This is due to the plugin not properly validating a token prior to updating a user's password. This makes it possible for unauthenticated attackers to change arbitrary user's passwords, including administrators, and leverage that to gain access to their account.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.8
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS probability
- 0.49%
- CWE
- CWE-620
- Published
- 2025-02-18
- Last modified
- 2026-03-13
Affected products
- scriptsbundle CarSpot – Dealership Wordpress Classified Theme
Weakness type
Related vulnerabilities
- CVE-2024-12824 — Nokri – Job Board WordPress Theme <= 1.6.2 - Unauthenticated Arbitrary Password Change
- CVE-2025-4322 — Motors <= 5.6.67 - Unauthenticated Privilege Escalation via Password Update/Account Takeover
- CVE-2024-20419 — A vulnerability in the authentication system of Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauth
- CVE-2025-1107 — Unverified password change vulnerability in Janto
- CVE-2024-33699 — The LevelOne WBR-6012 router's web application has a vulnerability in its firmware version R0.40e6, allowing attackers t
- CVE-2025-3603 — Flynax Bridge <= 2.2.0 - Unauthenticated Privilege Escalation via Password Update
- CVE-2025-4558 — WormHole Tech GPM - Unverified Password Change
- CVE-2025-2253 — IMITHEMES Listing <= 3.3 - Unauthenticated Privilege Escalation via Unverified Password Reset