Junglewise Threat Intelligence

CVE-2026-54814: StylemixThemes Motors Local File Inclusion in WordPress plugin

CVE-2026-54814 · Severity: high · CVSS 8.1 · Published 2026-06-17

Technologies: StylemixThemes Motors – Car Dealership & Classified Listings. Vendors: StylemixThemes.

Executive brief

The Motors plugin for WordPress, used for car dealership and classified listing websites, contains a security flaw that allows unauthorized users to access sensitive files on the server. An attacker could exploit this to read configuration files containing database credentials, potentially leading to a full site takeover or data breach. This vulnerability is considered high priority as it can be targeted in automated mass-exploitation campaigns.

Technical details

A Local File Inclusion (LFI) vulnerability exists in the StylemixThemes Motors plugin (versions up to 1.4.109) due to improper validation of user-supplied input used in PHP include or require statements (CWE-98). Although the CVSS vector indicates high complexity, the flaw allows an unauthenticated remote attacker to include and execute local files on the web server. This can lead to the disclosure of sensitive information, such as the wp-config.php file, or potentially remote code execution if the attacker can upload or influence the contents of a local file. The issue is resolved in version 1.4.110.

Affected products

  • StylemixThemes Motors - Car Dealership Classified Listings up to 1.4.109

Timeline

  • 2026-03-29: other: Reported by researcher endy
  • 2026-06-17: disclosed: Vulnerability published by Patchstack and NVD
  • 2026-06-17: patched: Patch released in version 1.4.110

References

Related threats