Vehica Core
by WordPress
CVEs (3)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-3105 | Hig | 0.57 | 8.8 | 0.00 | Apr 4, 2025 | The Vehica Core plugin for WordPress, used by the Vehica - Car Dealer & Listing WordPress Theme, is vulnerable to privilege escalation in all versions up to, and including, 1.0.97. This is due to the plugin not properly validating user meta fields prior to updating them in the… | ||
| CVE-2026-66654 | Med | 0.39 | 6.0 | 0.00 | Aug 13, 2026 | Subscriber Server Side Request Forgery (SSRF) in Vehica Core <= 1.0.104 versions. | ||
| CVE-2025-60117 | Med | 0.28 | 4.3 | 0.00 | Sep 26, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in TangibleWP Vehica Core vehica-core allows Cross Site Request Forgery.This issue affects Vehica Core: from n/a through <= 1.0.100. |
- risk 0.57cvss 8.8epss 0.00
The Vehica Core plugin for WordPress, used by the Vehica - Car Dealer & Listing WordPress Theme, is vulnerable to privilege escalation in all versions up to, and including, 1.0.97. This is due to the plugin not properly validating user meta fields prior to updating them in the…
- risk 0.39cvss 6.0epss 0.00
Subscriber Server Side Request Forgery (SSRF) in Vehica Core <= 1.0.104 versions.
- risk 0.28cvss 4.3epss 0.00
Cross-Site Request Forgery (CSRF) vulnerability in TangibleWP Vehica Core vehica-core allows Cross Site Request Forgery.This issue affects Vehica Core: from n/a through <= 1.0.100.