Executive brief
The MotorDesk plugin for WordPress, which is used to manage automotive dealership listings, contains a security flaw that allows attackers to change its configuration. By tricking a site administrator into clicking a malicious link, an attacker can modify settings such as the search page location or template paths. This could lead to website disruption or redirection of users to unauthorized pages.
Technical details
The MotorDesk plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) due to missing or incorrect nonce validation on the motordesk_admin_home function. An unauthenticated attacker can exploit this by inducing a site administrator to perform an action, such as clicking a link, which triggers a forged request. Successful exploitation allows the attacker to modify plugin configuration settings, including the search page URI and custom template directory path. This affects all versions up to and including 1.1.2.
Affected products
- MotorDesk MotorDesk <= 1.1.2
Timeline
- 2026-06-24: disclosed
- 2026-06-24: advisory
References
- https://plugins.trac.wordpress.org/browser/motordesk/trunk/include/motordesk_admin.php
- https://plugins.trac.wordpress.org/browser/motordesk/trunk/include/motordesk_admin.php
- https://plugins.trac.wordpress.org/browser/motordesk/trunk/include/motordesk_admin.php
- https://plugins.trac.wordpress.org/browser/motordesk/trunk/include/motordesk_admin.php
- https://www.wordfence.com/threat-intel/vulnerabilities/id/5e3e9421-809c-423a-afcf-28c061c00fad?source=cve