cardealer_install_plugin
AJAX action, which makes it possible for authenticated attackers with a role as low as subscriber to install and activate arbitrary plugins from WordPress.org repository. Car Dealer by Bill Minozzi <= 3.04 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Installation
REPORT ID: 7cfb0c84-bcca-4f66-8854-0edee25ef18a
The plugin contains a Missing Authorization vulnerability due to a missing capability check in the
You need to log in to view the vulnerability details.