CVE-2025-1282 | ThemeMakers Car Dealer Automotive Theme up to 1.6.3 on WordPress wp-config.php delete_post_photo/add_car path traversal
A vulnerability was found in ThemeMakers Car Dealer Automotive Theme up to 1.6.3 on WordPress. It has been rated as critical. This issue affects the function delete_post_photo/add_car of the file wp-config.php. The manipulation leads to path traversal.
The identification of this vulnerability is CVE-2025-1282. The attack may be initiated remotely. There is no exploit available.