Junglewise Threat Intelligence

CVE-2026-12435: Stylemix Motors Plugin authorization bypass in stm_mark_as_sold_car

CVE-2026-12435 · Severity: medium · CVSS 4.3 · Published 2026-07-01

Technologies: StylemixThemes Motors – Car Dealership & Classified Listings. Vendors: StylemixThemes.

Executive brief

The Motors plugin for WordPress, used to manage car dealership and classified listings, contains a security flaw that allows registered users to interfere with other people's listings. An attacker can falsely mark any vehicle on the site as 'Sold' or remove its 'Featured' status. This could disrupt business operations, mislead potential buyers, and damage the reputation of legitimate sellers on the platform.

Technical details

The Motors plugin for WordPress is vulnerable to a missing authorization check (CWE-862) in the 'stm_mark_as_sold_car' action within the vehicle_functions.php file. Authenticated attackers with Subscriber-level permissions can exploit this by harvesting a valid security nonce from their own active listing and replaying it against an arbitrary victim's post ID. Successful exploitation allows the attacker to trigger a site-wide 'Sold' badge on the victim's listing and silently strip the 'special_car' featured post meta. The vulnerability exists in all versions up to and including 1.4.111.

Affected products

  • StylemixThemes Motors – Car Dealership & Classified Listings Plugin up to, and including, 1.4.111

Timeline

  • 2026-07-01: advisory
  • 2026-07-01: disclosed

References

Related threats