Thème WordPress

Vulnérabilités Car Dealer Automotive WordPress Theme – Responsive

Cette page rassemble les failles publiées pour Car Dealer Automotive WordPress Theme – Responsive, leurs plages de versions affectées et les correctifs signalés dans la base locale.

7Vulnérabilités
1Critiques
7Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Car Dealer Automotive WordPress Theme – Responsive

7 fiches

CVE-2026-24391 Moyenne · 6,1
Car Dealer Automotive WordPress Theme – Responsive

Car Dealer Automotive WordPress Theme – Responsive <= 1.6.7 – Reflected Cross-Site Scripting

The Car Dealer Automotive WordPress Theme – Responsive theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.6.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…

Versions affectées

*-1.6.7

Correctif

1.6.8

Publication

23/03/2026

CVE-2025-1687 Élevée · 8,8
Car Dealer Automotive WordPress Theme – Responsive

Cardealer <= 1.6.4 – Cross-Site Request Forgery to User Update via update_user_profile

The Cardealer theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.6.4. This is due to missing nonce validation on the 'update_user_profile' function. This makes it possible for unauthenticated attackers to update…

Versions affectées

*-1.6.4

Correctif

1.6.5

Publication

27/02/2025

CVE-2025-1682 Élevée · 8,8
Car Dealer Automotive WordPress Theme – Responsive

Cardealer <= 1.6.4 – Arbitrary Theme Option Update to Authenticated (Subscriber+) Privilege Escalation

The Cardealer theme for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.6.4 due to missing capability check on the 'save_settings' function. This makes it possible for authenticated attackers, with subscriber-level access and above,…

Versions affectées

*-1.6.4

Correctif

1.6.5

Publication

27/02/2025

CVE-2025-1681 Moyenne · 5,4
Car Dealer Automotive WordPress Theme – Responsive

Cardealer <= 1.6.4 – Missing Authorization to Authenticated (Subscriber+) Change and Delete JS and CSS Files

The Cardealer theme for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check and missing filename sanitization on the demo theme scheme AJAX functions in versions up to, and…

Versions affectées

*-1.6.4

Correctif

1.6.5

Publication

27/02/2025

CVE-2025-1282 Élevée · 8,8
Car Dealer Automotive WordPress Theme – Responsive

Car Dealer Automotive WordPress Theme – Responsive <= 1.6.3 – Authenticated (Subscriber+) Arbitrary File Deletion and Read

The Car Dealer Automotive WordPress Theme – Responsive theme for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_post_photo() and add_car() functions in all versions up to, and including, 1.6.3. This…

Versions affectées

*-1.6.3

Correctif

1.6.4

Publication

26/02/2025

CVE-2015-9482 Élevée · 7,5
Car Dealer Automotive WordPress Theme – Responsive

Car Dealer Automotive WordPress Theme < 1.1.9 – Sensitive Information Disclosure

The ThemeMakers Car Dealer / Auto Dealer Responsive theme before 1.1.9 for WordPress allows remote attackers to obtain sensitive information (such as user_login, user_pass, and user_email values) via a direct request for the wp-content/uploads/tmm_db_migrate/wp_users.dat URI.

Versions affectées

[*, 1.1.9)

Correctif

1.1.9

Publication

15/05/2015

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités