Junglewise Threat Intelligence

CVE-2026-54828: StylemixThemes Motors broken access control

CVE-2026-54828 · Severity: high · CVSS 7.5 · Published 2026-06-25

Technologies: StylemixThemes Motors – Car Dealership & Classified Listings. Vendors: StylemixThemes.

Executive brief

The Motors plugin for WordPress, which provides car dealership and classified listing functionality, contains a security flaw that allows unauthorized users to perform actions they should not be able to. An attacker could exploit this to modify site data or settings without needing a password or account. This could lead to unauthorized changes to vehicle listings or site configuration, potentially impacting the integrity of the dealership's online operations.

Technical details

The Motors plugin (motors-car-dealership-classified-listings) for WordPress is vulnerable to broken access control due to missing authorization checks (CWE-862) in versions up to 1.4.109. This allows an unauthenticated remote attacker to execute functions or actions that should be restricted to higher-privileged users. The vulnerability has a CVSS score of 7.5, indicating high integrity impact without direct confidentiality or availability loss. The issue is resolved in version 1.4.110.

Affected products

  • StylemixThemes Motors - Car Dealership & Classified Listings <= 1.4.109

Timeline

  • 2026-05-07: other: Reported by researcher HaiND
  • 2026-06-17: disclosed: Vulnerability disclosed by Patchstack
  • 2026-06-25: advisory: CVE published in NVD

References

Related threats