CVE-2025-2807
HIGHMotors Plugin <= 1.4.64 - Authenticated Arbitrary Plugin Installation
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2025-2807. PoCs published by Boshe99, Nxploited.
AI-analyzed exploit summary The repository contains functional exploit code for CVE-2025-2807, targeting an arbitrary file upload vulnerability in the WordPress Plugin 3DPrint Lite 1.9.1.4. The exploit demonstrates the ability to upload a malicious file to a vulnerable target.
Description
The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to arbitrary plugin installations due to a missing capability check in the mvl_setup_wizard_install_plugin() function in all versions up to, and including, 1.4.64. This makes it possible for authenticated attackers, with Subscriber-level access and above, to install and activate arbitrary plugins on the affected site's server which may make remote code execution possible.
Exploits (2)
The repository contains functional exploit code for CVE-2025-2807, targeting an arbitrary file upload vulnerability in the WordPress Plugin 3DPrint Lite 1.9.1.4. The exploit demonstrates the ability to upload a malicious file to a vulnerable target.
This exploit leverages a missing authorization check in the Motors WordPress plugin (≤1.4.64) to allow authenticated subscribers to install arbitrary plugins via the `mvl_setup_wizard_install_plugin` AJAX action. The PoC automates login, nonce extraction, and plugin installation.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H