Junglewise Threat Intelligence

CVE-2026-3892: StylemixThemes Motors Plugin arbitrary file deletion in dealer logo upload

CVE-2026-3892 · Severity: high · CVSS 8.1 · Published 2026-05-14

Technologies: StylemixThemes Motors – Car Dealership & Classified Listings. Vendors: StylemixThemes.

Executive brief

The Motors plugin for WordPress, which provides car dealership and classified listing functionality, contains a security flaw that allows users to delete files from the web server. An attacker with a basic user account could exploit this to remove critical website files, potentially leading to a complete site shutdown or the bypass of security configurations. This could result in significant operational downtime and loss of website data.

Technical details

The vulnerability is classified as an arbitrary file deletion (CWE-73) resulting from insufficient file path validation within the 'become-dealer' logo upload flow. Specifically, the plugin's profile update handler allows authenticated users to provide an arbitrary filesystem path. An attacker with at least subscriber-level privileges can exploit this by sending a crafted request to delete sensitive files on the server, such as wp-config.php, which could lead to site takeover or denial of service. The issue affects all versions up to and including 1.4.107; a fix was introduced in changeset 3505874.

Affected products

  • StylemixThemes Motors – Car Dealership & Classified Listings Plugin up to, and including, 1.4.107

Timeline

  • 2026-05-14: disclosed
  • 2026-05-14: advisory

References

Related threats