Junglewise Threat Intelligence

CVE-2026-54812: StylemixThemes Motors Blind SQL injection

CVE-2026-54812 · Severity: critical · CVSS 9.3 · Published 2026-06-17

Technologies: StylemixThemes Motors – Car Dealership & Classified Listings. Vendors: StylemixThemes.

Executive brief

The Motors plugin for WordPress, which provides car dealership and classified listing functionality, contains a critical security flaw. An attacker can use this vulnerability to interact directly with the website's database without needing a password. This could lead to the theft of sensitive customer information or the disruption of site operations.

Technical details

A Blind SQL Injection vulnerability exists in the StylemixThemes Motors plugin for WordPress due to improper neutralization of special elements used in SQL commands. The flaw allows an unauthenticated remote attacker to execute arbitrary SQL queries against the backend database. By sending specially crafted network requests, an attacker can extract sensitive data or potentially impact database availability. The vulnerability is present in versions up to and including 1.4.109 and has been addressed in version 1.4.110.

Affected products

  • StylemixThemes Motors - Car Dealership Classified Listings up to 1.4.109

Timeline

  • 2026-03-29: other: Reported by researcher endy
  • 2026-06-17: advisory: Advisory published by Patchstack and NVD
  • 2026-06-17: patched: Patch released in version 1.4.110

References

Related threats