VYPR

Vehica Core

by WordPress

CVEs (3)

  • CVE-2025-3105HigApr 4, 2025
    risk 0.57cvss 8.8epss 0.00

    The Vehica Core plugin for WordPress, used by the Vehica - Car Dealer & Listing WordPress Theme, is vulnerable to privilege escalation in all versions up to, and including, 1.0.97. This is due to the plugin not properly validating user meta fields prior to updating them in the…

  • CVE-2026-66654MedAug 13, 2026
    risk 0.39cvss 6.0epss 0.00

    Subscriber Server Side Request Forgery (SSRF) in Vehica Core <= 1.0.104 versions.

  • CVE-2025-60117MedSep 26, 2025
    risk 0.28cvss 4.3epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in TangibleWP Vehica Core vehica-core allows Cross Site Request Forgery.This issue affects Vehica Core: from n/a through <= 1.0.100.