Executive brief
The Motors theme for WordPress, commonly used for automotive dealership websites, contains a security flaw that allows unauthorized individuals to perform actions they should not have access to. Because this issue does not require a login, an attacker could potentially modify site settings or disrupt website operations. This could lead to unauthorized changes to vehicle listings or temporary service outages, impacting the business's online presence and customer trust.
Technical details
The Motors theme for WordPress (versions up to and including 5.6.80) suffers from a broken access control vulnerability due to missing authorization checks (CWE-862). This flaw allows an unauthenticated remote attacker to execute functions that should be restricted to higher-privileged users. The attack vector is network-based and requires no user interaction or prior authentication. Successful exploitation can lead to unauthorized integrity changes or availability impacts on the affected WordPress site. As of the advisory date, no official patch has been released by the developer.
Affected products
- StylemixThemes Motors <= 5.6.80
Timeline
- 2025-10-15: disclosed: Reported by Rafie Muhammad to Patchstack
- 2026-06-30: advisory: Initial advisory published by Patchstack
- 2026-07-02: other: CVE record published and added to NVD dataset