VYPR

Motors – Car Dealer, Classifieds & Listing

by Stellarwp

Source repositories

CVEs (12)

  • CVE-2022-3989HigDec 12, 2022
    risk 0.57cvss 8.8epss 0.01

    The Motors WordPress plugin before 1.4.4 does not properly validate uploaded files for dangerous file types (such as .php) in an AJAX action, allowing an attacker to sign up on a victim's WordPress instance, upload a malicious PHP file and attempt to launch a brute-force attack…

  • CVE-2025-2807HigApr 8, 2025
    risk 0.50cvss 8.8epss 0.01

    The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to arbitrary plugin installations due to a missing capability check in the mvl_setup_wizard_install_plugin() function in all versions up to, and including, 1.4.64. This makes it…

  • CVE-2023-46208HigOct 27, 2023
    risk 0.46cvss 7.1epss 0.00

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in StylemixThemes Motors – Car Dealer, Classifieds & Listing plugin <= 1.4.6 versions.

  • CVE-2019-17228MedFeb 24, 2020
    risk 0.42cvss 6.5epss 0.01

    includes/options.php in the motors-car-dealership-classified-listings (aka Motors - Car Dealer & Classified Ads) plugin through 1.4.0 for WordPress allows unauthenticated options changes.

  • CVE-2019-17229MedFeb 24, 2020
    risk 0.40cvss 6.1epss 0.01

    includes/options.php in the motors-car-dealership-classified-listings (aka Motors - Car Dealer & Classified Ads) plugin through 1.4.0 for WordPress has multiple stored XSS issues.

  • CVE-2024-10970MedJan 16, 2025
    risk 0.35cvss 5.4epss 0.00

    The The Motors – Car Dealer, Classifieds & Listing plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.4.43. This is due to the software allowing users to execute an action that does not properly validate a value before…

  • CVE-2022-38716MedMay 25, 2023
    risk 0.35cvss 5.4epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in StylemixThemes Motors – Car Dealer, Classifieds & Listing plugin <= 1.4.4 versions.

  • CVE-2024-5545MedJul 2, 2024
    risk 0.34cvss 5.3epss 0.00

    The Motors – Car Dealer, Classifieds & Listing plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the stm_edit_delete_user_car function in all versions up to, and including, 1.4.8. This makes it possible for…

  • CVE-2025-3437MedApr 8, 2025
    risk 0.28cvss 4.3epss 0.00

    The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several functions in the ajax_actions.php file in all versions up to, and including, 1.4.66. This makes it…

  • CVE-2025-2808MedApr 8, 2025
    risk 0.28cvss 5.4epss 0.00

    The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Phone Number parameter in all versions up to, and including, 1.4.63 due to insufficient input sanitization and output escaping. This makes it…

  • CVE-2023-46207MedNov 13, 2023
    risk 0.27cvss 4.1epss 0.01

    Server-Side Request Forgery (SSRF) vulnerability in StylemixThemes Motors – Car Dealer, Classifieds & Listing.This issue affects Motors – Car Dealer, Classifieds & Listing: from n/a through 1.4.6.

  • CVE-2024-13737MedMar 22, 2025
    risk 0.21cvss 4.3epss 0.00

    The Motors – Car Dealer, Classifieds & Listing plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability checks on the motors_create_template and motors_delete_template functions in all versions up to, and including, 1.4.57. This makes…