Executive brief
The Motors plugin for WordPress, which provides car dealership and classified listing functionality, contains a security flaw that allows unauthorized users to perform actions they should not be able to. An attacker could exploit this to modify site data or settings without needing a password or account. This could lead to unauthorized changes to vehicle listings or site configuration, potentially impacting the integrity of the dealership's online operations.
Technical details
The Motors plugin (motors-car-dealership-classified-listings) for WordPress is vulnerable to broken access control due to missing authorization checks (CWE-862) in versions up to 1.4.109. This allows an unauthenticated remote attacker to execute functions or actions that should be restricted to higher-privileged users. The vulnerability has a CVSS score of 7.5, indicating high integrity impact without direct confidentiality or availability loss. The issue is resolved in version 1.4.110.
Affected products
- StylemixThemes Motors - Car Dealership & Classified Listings <= 1.4.109
Timeline
- 2026-05-07: other: Reported by researcher HaiND
- 2026-06-17: disclosed: Vulnerability disclosed by Patchstack
- 2026-06-25: advisory: CVE published in NVD