← Back

Motors Car Dealer, Classifieds & Listing

motors_-_car_dealer,_classifieds_&_listing

Vendor: Stylemixthemes • 12 CVEs

CVEs (12)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Stylemixthemes
1Motors Car Dealer, Classifieds & Listing
Aug 8, 2025
Apr 8, 2025
N/A· v4
4.3 MEDIUM· v3
N/A· v2
The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several functions in the ajax_actions.php file in all...Show more
The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several functions in the ajax_actions.php file in all versions up to, and including, 1.4.66. This makes it possible for authenticated attackers, with Subscriber-level access and above, to execute several initial set-up actions.Show less
1Stylemixthemes
1Motors Car Dealer, Classifieds & Listing
Aug 8, 2025
Apr 8, 2025
N/A· v4
5.4 MEDIUM· v3
N/A· v2
The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Phone Number parameter in all versions up to, and including, 1.4.63 due to insufficient i...Show more
The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Phone Number parameter in all versions up to, and including, 1.4.63 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.Show less
1Stylemixthemes
1Motors Car Dealer, Classifieds & Listing
Aug 8, 2025
Apr 8, 2025
N/A· v4
8.8 HIGH· v3
N/A· v2
The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to arbitrary plugin installations due to a missing capability check in the mvl_setup_wizard_install_plugin() function in all ver...Show more
The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to arbitrary plugin installations due to a missing capability check in the mvl_setup_wizard_install_plugin() function in all versions up to, and including, 1.4.64. This makes it possible for authenticated attackers, with Subscriber-level access and above, to install and activate arbitrary plugins on the affected site's server which may make remote code execution possible.Show less
1Stylemixthemes
1Motors Car Dealer, Classifieds & Listing
Mar 27, 2025
Mar 22, 2025
N/A· v4
4.3 MEDIUM· v3
N/A· v2
The Motors – Car Dealer, Classifieds & Listing plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability checks on the motors_create_template and motors_delete_template functions...Show more
The Motors – Car Dealer, Classifieds & Listing plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability checks on the motors_create_template and motors_delete_template functions in all versions up to, and including, 1.4.57. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary posts or create listing templates. This issue requires Elementor plugin to be installed, which is a required plugin for Motors Starter Theme.Show less
1Stylemixthemes
1Motors Car Dealer, Classifieds & Listing
Aug 8, 2025
Jan 16, 2025
N/A· v4
5.4 MEDIUM· v3
N/A· v2
The The Motors – Car Dealer, Classifieds & Listing plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.4.43. This is due to the software allowing users to execute a...Show more
The The Motors – Car Dealer, Classifieds & Listing plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.4.43. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for authenticated attackers, with Subscriber-level access and above, to execute arbitrary shortcodes.Show less
1Stylemixthemes
1Motors Car Dealer, Classifieds & Listing
Apr 8, 2026
Jul 2, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
The Motors – Car Dealer, Classifieds & Listing plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the stm_edit_delete_user_car function in all versions up to, and...Show more
The Motors – Car Dealer, Classifieds & Listing plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the stm_edit_delete_user_car function in all versions up to, and including, 1.4.8. This makes it possible for unauthenticated attackers to unpublish arbitrary posts and pages.Show less
1Stylemixthemes
1Motors Car Dealer, Classifieds & Listing
Apr 28, 2026
Nov 13, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Server-Side Request Forgery (SSRF) vulnerability in StylemixThemes Motors – Car Dealer, Classifieds & Listing.This issue affects Motors – Car Dealer, Classifieds & Listing: from n/a through 1.4.6.
1Stylemixthemes
1Motors Car Dealer, Classifieds & Listing
Nov 21, 2024
Oct 27, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in StylemixThemes Motors – Car Dealer, Classifieds & Listing plugin <= 1.4.6 versions.
1Stylemixthemes
1Motors Car Dealer, Classifieds & Listing
Nov 21, 2024
May 25, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Cross-Site Request Forgery (CSRF) vulnerability in StylemixThemes Motors – Car Dealer, Classifieds & Listing plugin <= 1.4.4 versions.
1Stylemixthemes
1Motors Car Dealer, Classifieds & Listing
Apr 22, 2025
Dec 12, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
The Motors WordPress plugin before 1.4.4 does not properly validate uploaded files for dangerous file types (such as .php) in an AJAX action, allowing an attacker to sign up on a victim's WordPress instance, upload a mal...Show more
The Motors WordPress plugin before 1.4.4 does not properly validate uploaded files for dangerous file types (such as .php) in an AJAX action, allowing an attacker to sign up on a victim's WordPress instance, upload a malicious PHP file and attempt to launch a brute-force attack to discover the uploaded payload.Show less
1Stylemixthemes
1Motors Car Dealer, Classifieds & Listing
Nov 21, 2024
Feb 24, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
includes/options.php in the motors-car-dealership-classified-listings (aka Motors - Car Dealer & Classified Ads) plugin through 1.4.0 for WordPress has multiple stored XSS issues.
1Stylemixthemes
1Motors Car Dealer, Classifieds & Listing
Nov 21, 2024
Feb 24, 2020
N/A· v4
6.5 MEDIUM· v3
6.4 MEDIUM· v2
includes/options.php in the motors-car-dealership-classified-listings (aka Motors - Car Dealer & Classified Ads) plugin through 1.4.0 for WordPress allows unauthenticated options changes.