Junglewise Threat Intelligence

CVE-2026-39515: StylemixThemes Motors broken access control in WordPress plugin

CVE-2026-39515 · Severity: medium · CVSS 6.5 · Published 2026-06-15

Technologies: StylemixThemes Motors – Car Dealership & Classified Listings. Vendors: StylemixThemes.

Executive brief

The Motors plugin for WordPress, which is used to manage car dealership and classified listings, contains a security flaw that allows users with basic 'Subscriber' accounts to perform unauthorized actions. An attacker with a low-level account could exploit this lack of access control to disrupt the website's availability. This could lead to service outages or operational downtime for the dealership's online platform.

Technical details

A broken access control vulnerability (CWE-862: Missing Authorization) exists in the Motors plugin for WordPress in versions prior to 1.4.107. The flaw allows an authenticated attacker with Subscriber-level privileges to execute functions that lack proper authorization checks. According to the CVSS vector, the primary impact of this exploit is on system availability (High), suggesting that an attacker can trigger actions that lead to a denial-of-service condition. The vulnerability is reachable over the network without user interaction, provided the attacker has a valid low-privileged account. A patch is available in version 1.4.107.

Affected products

  • StylemixThemes Motors - Car Dealership Classified Listings < 1.4.107

Timeline

  • 2026-03-04: other: Reported by Jakub Herman
  • 2026-04-21: advisory: Initial disclosure by Patchstack
  • 2026-06-15: disclosed: NVD publication date

References

Related threats