The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including, 1.4.107. This is due to insufficient file path validation in the become-dealer logo upload flow. The plugin allows any authenticated user to set an arbitrary filesystem path via the profile update handler. This makes it possible for authenticated attackers, with subscriber level access and above, to delete arbitrary files on the server.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
The Motors – Car Dealership & Classified Listings Plugin for WordPress contains a critical arbitrary file deletion vulnerability (CVE-2026-3892, CVSS 8.1) affecting all versions up to 1.4.107. The vulnerability exists in the become-dealer logo upload functionality, where insufficient file path validation allows authenticated users with subscriber-level privileges to specify arbitrary filesystem paths during profile updates. This means an attacker with basic account access can craft malicious requests to delete critical files on the web server, potentially removing application files, configuration files, or other sensitive data necessary for site operation. The vulnerability is particularly dangerous because it requires only low-privilege authentication and can lead to complete site compromise, data loss, or denial of service.
While this CVE currently maps to CWE-73 (External Control of File Name or Path) and has no direct MITRE ATT&CK technique mapping, Casky's security skills—powered by Claude AI's extended reasoning—would identify related attack patterns such as Defense Evasion (T1070 - Indicator Removal on Host), Impact (T1531 - Account Access Removal, T1485 - Data Destruction), and Lateral Movement techniques involving file system manipulation. Practitioners using Casky would observe detection findings revealing suspicious profile update requests containing path traversal sequences (../, absolute paths), unauthorized file deletion attempts in server logs, and unexpected modifications to the become-dealer upload handler parameters. The platform's 754 mapped skills enable practitioners to correlate these file deletion patterns with account activity timelines, identify which authenticated sessions performed deletions, and trace the attack back to specific user accounts for incident response and forensic investigation.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-3892. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation