VYPR

Motors

by WordPress

Source repositories

CVEs (12)

  • CVE-2025-4322CriMay 20, 2025
    risk 0.65cvss 9.8epss 0.19

    The Motors theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 5.6.67. This is due to the theme not properly validating a user's identity prior to updating their password. This makes it possible for unauthenticated…

  • CVE-2025-64374CriDec 18, 2025
    risk 0.64cvss 9.9epss 0.00

    Unrestricted Upload of File with Dangerous Type vulnerability in StylemixThemes Motors motors allows Using Malicious Files.This issue affects Motors: from n/a through <= 5.6.81.

  • CVE-2022-3989HigDec 12, 2022
    risk 0.57cvss 8.8epss 0.01

    The Motors WordPress plugin before 1.4.4 does not properly validate uploaded files for dangerous file types (such as .php) in an AJAX action, allowing an attacker to sign up on a victim's WordPress instance, upload a malicious PHP file and attempt to launch a brute-force attack…

  • CVE-2025-10494HigOct 8, 2025
    risk 0.53cvss 8.1epss 0.00

    The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation when deleting profile pictures in all versions up to, and including, 1.4.89. This makes it possible for authenticated…

  • CVE-2025-2807HigApr 8, 2025
    risk 0.50cvss 8.8epss 0.01

    The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to arbitrary plugin installations due to a missing capability check in the mvl_setup_wizard_install_plugin() function in all versions up to, and including, 1.4.64. This makes it…

  • CVE-2024-13738HigMay 3, 2025
    risk 0.47cvss 7.3epss 0.00

    The The Motors - Car Dealer, Rental & Listing WordPress theme theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.6.65. This is due to the software allowing users to execute an action that does not properly validate a value…

  • CVE-2026-39515MedJun 15, 2026
    risk 0.42cvss 6.5epss 0.00

    Subscriber Broken Access Control in Motors < 1.4.107 versions.

  • CVE-2026-7859MedJun 22, 2026
    risk 0.34cvss 5.3epss 0.00

    The Motors WordPress plugin before 1.4.110 does not have proper authorisation and CSRF checks on one of its AJAX actions, allowing unauthenticated attackers to modify arbitrary post metadata, such as the gallery, featured image and, on WooCommerce sites, product prices.

  • CVE-2025-2808MedApr 8, 2025
    risk 0.28cvss 5.4epss 0.00

    The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Phone Number parameter in all versions up to, and including, 1.4.63 due to insufficient input sanitization and output escaping. This makes it…

  • CVE-2026-27433MedJul 2, 2026
    risk 0.00cvss 6.5epss 0.00

    Unauthenticated Broken Access Control in Motors <= 5.6.80 versions.

  • CVE-2026-54812CriJun 17, 2026
    risk 0.00cvss 9.3epss 0.00

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in StylemixThemes Motors allows Blind SQL Injection. This issue affects Motors: from n/a through 1.4.109.

  • CVE-2026-54814HigJun 17, 2026
    risk 0.00cvss 8.1epss 0.00

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in StylemixThemes Motors allows PHP Local File Inclusion. This issue affects Motors: from n/a through 1.4.109.