Search
Search Results (5 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-96563 | 2 Stylemixthemes, Wordpress-extensions | 2 Motors - Car Dealer\, Classifieds \& Listing, Motors | 2026-10-11 | 6.4 Medium |
| The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'stm_f_s' parameter in all versions up to, and including, 1.4.123 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The nonce required by the stm_ajax_add_a_car AJAX handler is emitted in wp_footer on every page, making it accessible to any authenticated user and removing any practical barrier to exploitation at the Subscriber level. | ||||
| CVE-2026-104399 | 2 Stylemix, Wordpress-extensions | 2 Motors, Motors | 2026-10-06 | N/A |
| Insertion of Sensitive Information Into Sent Data vulnerability in StylemixThemes Motors allows Retrieve Embedded Sensitive Data. This issue affects Motors: from n/a through 1.4.124. | ||||
| CVE-2026-91022 | 1 Wordpress-extensions | 1 Motors | 2026-10-02 | 6.8 Medium |
| The Motors WordPress plugin before 1.4.124 does not sanitise and escape a listing badge setting before outputting it inside an HTML attribute, allowing users with a custom, administrator-assigned listing-management role to inject arbitrary web scripts that execute when a listing is viewed by any visitor, including an administrator. | ||||
| CVE-2026-91023 | 1 Wordpress-extensions | 1 Motors | 2026-10-02 | 3.1 Low |
| The Motors WordPress plugin before 1.4.124 does not properly verify that a user is authorised to modify a listing before processing one of its listing management actions, allowing authenticated attackers with subscriber-level access and above to set metadata on posts they do not own, including overwriting product prices. Exploitation is possible only when WooCommerce is active and the Motors WordPress plugin before 1.4.124's paid featured-listing option is enabled, neither of which is a default configuration. | ||||
| CVE-2026-16750 | 2 Stylemixthemes, Wordpress-extensions | 2 Motors - Car Dealer, Classifieds & Listing, Motors – Car Dealership & Classified Listings | 2026-09-29 | 5.3 Medium |
| The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to unauthorized access of data due to missing authorization checks in mvl_ajax_dealer_load_cars() function in all versions up to, and including, 1.4.120. This makes it possible for unauthenticated attackers to retrieve draft, pending, private, and future car listings belonging to arbitrary users. | ||||
Page 1 of 1.