Junglewise Threat Intelligence

CVE-2026-13114: Stylemix Motors Car Dealership Stored XSS in Comment Content

CVE-2026-13114 · Severity: high · CVSS 7.2 · Published 2026-07-11

Technologies: StylemixThemes Motors – Car Dealership & Classified Listings. Vendors: StylemixThemes.

Executive brief

A popular WordPress plugin used for car dealership and classified listings is vulnerable to a security flaw that allows attackers to inject malicious scripts into the website. These scripts can be hidden within comment sections or user profile information and will automatically run in the browser of any visitor who views the affected page. This could lead to unauthorized actions being performed on behalf of site visitors or the theft of sensitive session information.

Technical details

The Motors plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to a failure to properly sanitize and escape user-supplied input in the comment content and user biographical information fields. An unauthenticated remote attacker can exploit this by submitting malicious JavaScript within these fields. Because the input is stored in the database and later rendered on the site without adequate protection, the script executes in the context of any user's browser who visits the compromised page. The vulnerability is present in all versions up to 1.4.112 and was addressed in a subsequent changeset.

Affected products

  • StylemixThemes Motors – Car Dealership & Classified Listings Plugin up to, and including, 1.4.112

Timeline

  • 2026-07-11: advisory: NVD publication date
  • 2026-07-11: disclosed: Wordfence disclosure date

References

Related threats