Thème WordPress
Vulnérabilités Car Dealer Automotive WordPress Theme – Responsive
Cette page rassemble les failles publiées pour Car Dealer Automotive WordPress Theme – Responsive, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Car Dealer Automotive WordPress Theme – Responsive
7 fiches
Car Dealer Automotive WordPress Theme – Responsive <= 1.6.7 – Reflected Cross-Site Scripting
The Car Dealer Automotive WordPress Theme – Responsive theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.6.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…
*-1.6.7
1.6.8
23/03/2026
Car Dealer < 1.6.7 – Unauthenticated PHP Object Injection
The Car Dealer theme for WordPress is vulnerable to PHP Object Injection in versions up to, and excluding, 1.6.7 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No known…
[*, 1.6.7)
1.6.7
22/05/2025
Cardealer <= 1.6.4 – Cross-Site Request Forgery to User Update via update_user_profile
The Cardealer theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.6.4. This is due to missing nonce validation on the 'update_user_profile' function. This makes it possible for unauthenticated attackers to update…
*-1.6.4
1.6.5
27/02/2025
Cardealer <= 1.6.4 – Arbitrary Theme Option Update to Authenticated (Subscriber+) Privilege Escalation
The Cardealer theme for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.6.4 due to missing capability check on the 'save_settings' function. This makes it possible for authenticated attackers, with subscriber-level access and above,…
*-1.6.4
1.6.5
27/02/2025
Cardealer <= 1.6.4 – Missing Authorization to Authenticated (Subscriber+) Change and Delete JS and CSS Files
The Cardealer theme for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check and missing filename sanitization on the demo theme scheme AJAX functions in versions up to, and…
*-1.6.4
1.6.5
27/02/2025
Car Dealer Automotive WordPress Theme – Responsive <= 1.6.3 – Authenticated (Subscriber+) Arbitrary File Deletion and Read
The Car Dealer Automotive WordPress Theme – Responsive theme for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_post_photo() and add_car() functions in all versions up to, and including, 1.6.3. This…
*-1.6.3
1.6.4
26/02/2025
Car Dealer Automotive WordPress Theme < 1.1.9 – Sensitive Information Disclosure
The ThemeMakers Car Dealer / Auto Dealer Responsive theme before 1.1.9 for WordPress allows remote attackers to obtain sensitive information (such as user_login, user_pass, and user_email values) via a direct request for the wp-content/uploads/tmm_db_migrate/wp_users.dat URI.
[*, 1.1.9)
1.1.9
15/05/2015
Thèmes également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.