Extension WordPress

Vulnérabilités Motors – Car Dealership & Classified Listings Plugin

Cette page rassemble les failles publiées pour Motors – Car Dealership & Classified Listings Plugin, leurs plages de versions affectées et les correctifs signalés dans la base locale.

26Vulnérabilités
2Critiques
26Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Motors – Car Dealership & Classified Listings Plugin

26 fiches

CVE-2026-13114 Élevée · 7,2
Motors – Car Dealership & Classified Listings Plugin

Motors <= 1.4.112 – Unauthenticated Stored Cross-Site Scripting via Comment Content and User Biographical Info

The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content and User Biographical Info in all versions up to, and including, 1.4.112 due to insufficient input sanitization…

Versions affectées

*-1.4.112

Correctif

1.4.113

Publication

10/07/2026

CVE-2026-12435 Moyenne · 4,3
Motors – Car Dealership & Classified Listings Plugin

Motors <= 1.4.111 – Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Meta Modification via 'stm_mark_as_sold_car' Parameter

The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.4.111. This is due to the plugin not properly verifying that a user is…

Versions affectées

*-1.4.111

Correctif

1.4.112

Publication

30/06/2026

CVE-2026-7859 Moyenne · 4,3
Motors – Car Dealership & Classified Listings Plugin

Motors – Car Dealership & Classified Listings Plugin < 1.4.110 – Cross-Site Request Forgery

The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to 1.4.110. This is due to missing or incorrect nonce validation on a function. This makes it…

Versions affectées

[*, 1.4.110)

Correctif

1.4.110

Publication

22/06/2026

CVE-2026-54812 Élevée · 7,5
Motors – Car Dealership & Classified Listings Plugin

Motors – Car Dealership & Classified Listings Plugin <= 1.4.109 – Unauthenticated SQL Injection

The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.4.109 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation…

Versions affectées

*-1.4.109

Correctif

1.4.110

Publication

17/06/2026

CVE-2026-54814 Élevée · 7,5
Motors – Car Dealership & Classified Listings Plugin

Motors – Car Dealership & Classified Listings Plugin <= 1.4.109 – Authenticated (Subscriber+) Local File Inclusion

The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.4.109. This makes it possible for authenticated attackers, with subscriber-level access and above, to…

Versions affectées

*-1.4.109

Correctif

1.4.110

Publication

17/06/2026

CVE-2026-54828 Moyenne · 5,3
Motors – Car Dealership & Classified Listings Plugin

Motors – Car Dealership & Classified Listings Plugin <= 1.4.109 – Missing Authorization

The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.4.109. This makes it possible for…

Versions affectées

*-1.4.109

Correctif

1.4.110

Publication

17/06/2026

CVE-2026-3892 Élevée · 8,1
Motors – Car Dealership & Classified Listings Plugin

Motors – Car Dealer, Classifieds & Listing <= 1.4.107 – Authenticated (Subscriber+) Arbitrary File Deletion via 'stm_dealer_logo_path' Parameter

The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including, 1.4.107. This is due to insufficient file path validation in the become-dealer logo…

Versions affectées

*-1.4.107

Correctif

1.4.108

Publication

13/05/2026

CVE-2026-1934 Moyenne · 4,3
Motors – Car Dealership & Classified Listings Plugin

Motors – Car Dealership & Classified Listings Plugin <= 1.4.103 – Missing Authorization to Authenticated (Subscriber+) Payment Bypass via 'stm_payment_status' Parameter

The Motors – Car Dealership & Classified Listings plugin for WordPress is vulnerable to Payment Bypass via insecure user meta update in all versions up to, and including, 1.4.103 This is due to the stm_save_user_extra_fields() function updating sensitive…

Versions affectées

*-1.4.103

Correctif

1.4.104

Publication

11/05/2026

CVE-2026-39515 Moyenne · 4,3
Motors – Car Dealership & Classified Listings Plugin

Motors – Car Dealership & Classified Listings Plugin < 1.4.107 – Missing Authorization

The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to 1.4.107. This makes it possible for authenticated attackers,…

Versions affectées

[*, 1.4.107)

Correctif

1.4.107

Publication

21/04/2026

CVE-2025-10494 Élevée · 8,1
Motors – Car Dealership & Classified Listings Plugin

Motors – Car Dealership & Classified Listings Plugin <= 1.4.89 – Authenticated (Subscriber+) Arbitrary File Deletion

The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation when deleting profile pictures in all versions up to, and including, 1.4.89. This makes…

Versions affectées

*-1.4.89

Correctif

1.4.90

Publication

07/10/2025

CVE-2025-2807 Élevée · 8,8
Motors – Car Dealership & Classified Listings Plugin

Motors – Car Dealership & Classified Listings Plugin <= 1.4.64 – Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Installation

The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to arbitrary plugin installations due to a missing capability check in the mvl_setup_wizard_install_plugin() function in all versions up to, and including, 1.4.64. This makes…

Versions affectées

*-1.4.64

Correctif

1.4.65

Publication

07/04/2025

CVE-2025-3437 Moyenne · 4,3
Motors – Car Dealership & Classified Listings Plugin

Motors – Car Dealership & Classified Listings Plugin <= 1.4.66 – Missing Authorization to Authenticated (Subscriber+) Wizard Set-up

The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several functions in the ajax_actions.php file in all versions up to, and…

Versions affectées

*-1.4.66

Correctif

1.4.67

Publication

07/04/2025

CVE-2025-2808 Moyenne · 5,4
Motors – Car Dealership & Classified Listings Plugin

Motors – Car Dealership & Classified Listings Plugin <= 1.4.63 – Authenticated (Subscriber+) Stored Cross-Site Scripting

The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Phone Number parameter in all versions up to, and including, 1.4.63 due to insufficient input sanitization and output…

Versions affectées

*-1.4.63

Correctif

1.4.64

Publication

07/04/2025

CVE-2025-32142 Élevée · 8,8
Motors – Car Dealership & Classified Listings Plugin

Motors <= 1.4.71 – Authenticated (Contributor+) Local File Inclusion

The Motors plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.4.71. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files on the…

Versions affectées

*-1.4.71

Correctif

1.4.72

Publication

04/04/2025

CVE-2025-32170 Moyenne · 6,4
Motors – Car Dealership & Classified Listings Plugin

Motors <= 1.4.71 – Authenticated (Contributor+) Stored Cross-Site Scripting

The Motors plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.4.71 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above,…

Versions affectées

*-1.4.71

Correctif

1.4.72

Publication

04/04/2025

CVE-2024-13737 Moyenne · 4,3
Motors – Car Dealership & Classified Listings Plugin

Motors – Car Dealer, Classifieds & Listing <= 1.4.57 – Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Deletion and Listing Template Creation

The Motors – Car Dealer, Classifieds & Listing plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability checks on the motors_create_template and motors_delete_template functions in all versions up to, and including, 1.4.57.…

Versions affectées

*-1.4.57

Correctif

1.4.58

Publication

21/03/2025

CVE-2024-10970 Moyenne · 5,4
Motors – Car Dealership & Classified Listings Plugin

Motors – Car Dealer, Classifieds & Listing <= 1.4.43 – Authenticated (Subscriber+) Arbitrary Shortcode Execution via Custom Title

The The Motors – Car Dealer, Classifieds & Listing plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.4.43. This is due to the software allowing users to execute an action…

Versions affectées

*-1.4.43

Correctif

1.4.44

Publication

15/01/2025

CVE-2024-5545 Moyenne · 5,3
Motors – Car Dealership & Classified Listings Plugin

Motors – Car Dealer, Classifieds & Listing <= 1.4.9 – Missing Authorization

The Motors – Car Dealer, Classifieds & Listing plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the stm_edit_delete_user_car function in all versions up to, and including, 1.4.8. This makes…

Versions affectées

*-1.4.9

Correctif

1.4.11

Publication

01/07/2024

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités