Website support, maintenance and fixes for UK businessesCall 0208 088 8371info@websupportservices.co.uk

HomeWordPress vulnerabilitiesMotors

Motors vulnerabilities

Motors has 20 known vulnerabilities in this database. The most recent published record is dated 6 Oct 2026.

Known vulnerabilities
20
Active installs
9,000+
Latest version
1.4.124
Last updated
29 Sep 2026
Most recent
6 Oct 2026

No fixed version has been published yet, so consider disabling, removing or replacing the plugin until a safe release is available.

Find it in your WordPress dashboard under Plugins. Severity is based on the CVSS score published with the CVE where one is available.

VulnerabilitySeverityAffectedFixPublished
Sensitive data exposure
CVE-2026-104399
Medium 6.9Up to 1.4.124No fixed version yet1 d ago
Cross-site scripting (XSS)
CVE-2026-91022
Medium 6.8Before 1.4.124Fixed in 1.4.1245 d ago
Broken access control
CVE-2026-91023
Low 3.1Before 1.4.124Fixed in 1.4.1245 d ago
SQL injection
CVE-2026-6806
High 7.5Up to 1.4.109Fixed in a later version (latest 1.4.124)7 d ago
Broken access control
CVE-2026-16750
Medium 5.3Up to 1.4.120Fixed in a later version (latest 1.4.124)17 Sep 2026
Broken access control
CVE-2026-91016
Medium 5.3Before 1.4.121Fixed in 1.4.12117 Sep 2026
Cross-site scripting (XSS)
CVE-2026-13114
High 7.2Up to 1.4.112Fixed in a later version (latest 1.4.124)11 Jul 2026
Broken access control
CVE-2026-12435
Medium 4.3Up to 1.4.111Fixed in a later version (latest 1.4.124)1 Jul 2026
Cross-site request forgery (CSRF)
CVE-2026-7859
Medium 5.3Before 1.4.110Fixed in 1.4.11022 Jun 2026
Arbitrary file deletion
CVE-2026-3892
High 8.1Up to 1.4.107Fixed in a later version (latest 1.4.124)14 May 2026
Broken access control
CVE-2026-1934
Medium 4.3Up to 1.4.103Fixed in a later version (latest 1.4.124)12 May 2026
Remote code execution
CVE-2025-10494
High 8.1Up to 1.4.89Fixed in a later version (latest 1.4.124)8 Oct 2025
Broken access control
CVE-2025-3437
Medium 4.3Before 1.4.67Fixed in 1.4.678 Apr 2025
Cross-site scripting (XSS)
CVE-2025-2808
Medium 5.4Before 1.4.64Fixed in 1.4.648 Apr 2025
Remote code execution
CVE-2025-2807
High 8.8Before 1.4.65Fixed in 1.4.658 Apr 2025
Broken access control
CVE-2024-13737
Medium 4.3Before 1.4.58Fixed in 1.4.5822 Mar 2025
Remote code execution
CVE-2024-10970
Medium 5.4Before 1.4.44Fixed in 1.4.4416 Jan 2025
Security weakness
CVE-2022-3989
High 8.8Before 1.4.4Fixed in 1.4.412 Dec 2022
Cross-site scripting (XSS)
CVE-2019-17229
Medium 6.1Up to 1.4.0Fixed in a later version (latest 1.4.124)24 Feb 2020
Security weakness
CVE-2019-17228
Medium 6.5Up to 1.4.0Fixed in a later version (latest 1.4.124)24 Feb 2020
Read the published descriptions
CVE-2026-104399, 6 Oct 2026
Insertion of Sensitive Information Into Sent Data vulnerability in StylemixThemes Motors allows Retrieve Embedded Sensitive Data. This issue affects Motors: from n/a through 1.4.124. CVE record
CVE-2026-91022, 2 Oct 2026
The Motors WordPress plugin before 1.4.124 does not sanitise and escape a listing badge setting before outputting it inside an HTML attribute, allowing users with a custom, administrator-assigned listing-management role to inject arbitrary web scripts that execute when a listing is viewed by any visitor, including an administrator. CVE record
CVE-2026-91023, 2 Oct 2026
The Motors WordPress plugin before 1.4.124 does not properly verify that a user is authorised to modify a listing before processing one of its listing management actions, allowing authenticated attackers with subscriber-level access and above to set metadata on posts they do not own, including overwriting product prices. Exploitation is possible only when WooCommerce is active and the Motors WordPress plugin before 1.4.124's paid featured-listing option is enabled, neither of which is a default configuration. CVE record
CVE-2026-6806, 30 Sep 2026
The Motors - Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'stm_lat/stm_lng' parameter in all versions up to, and including, 1.4.109 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. CVE record
CVE-2026-16750, 17 Sep 2026
The Motors - Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to unauthorized access of data due to missing authorization checks in mvl_ajax_dealer_load_cars() function in all versions up to, and including, 1.4.120. This makes it possible for unauthenticated attackers to retrieve draft, pending, private, and future car listings belonging to arbitrary users. CVE record
CVE-2026-91016, 17 Sep 2026
The Motors WordPress plugin before 1.4.121 does not verify that a request is authorized to view a user's non-published listings before returning them, allowing unauthenticated attackers to read any author's draft, pending and private car listings - including titles, prices, media URLs and seller notes - by supplying only the target's numeric user id. CVE record
CVE-2026-13114, 11 Jul 2026
The Motors - Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content and User Biographical Info in all versions up to, and including, 1.4.112 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2026-12435, 1 Jul 2026
The Motors - Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.4.111. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to mark or unmark any other user's car listing as sold by replaying a valid nonce harvested from their own listing against an arbitrary victim post ID, triggering a site-wide 'Sold' badge on the victim's listing and silently stripping its special_car featured post meta as a side effect. Exploitation requires the attacker to hold an active listing of their own (obtainable by a Subscriber via the plugin's add-listing form) in order to harvest a valid nonce for the 'stm_mark_as_sold_car' action, which can then be replayed against any other listing's post ID. CVE record
CVE-2026-7859, 22 Jun 2026
The Motors WordPress plugin before 1.4.110 does not have proper authorisation and CSRF checks on one of its AJAX actions, allowing unauthenticated attackers to modify arbitrary post metadata, such as the gallery, featured image and, on WooCommerce sites, product prices. CVE record
CVE-2026-3892, 14 May 2026
The Motors - Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including, 1.4.107. This is due to insufficient file path validation in the become-dealer logo upload flow. The plugin allows any authenticated user to set an arbitrary filesystem path via the profile update handler. This makes it possible for authenticated attackers, with subscriber level access and above, to delete arbitrary files on the server. CVE record
CVE-2026-1934, 12 May 2026
The Motors - Car Dealership & Classified Listings plugin for WordPress is vulnerable to Payment Bypass via insecure user meta update in all versions up to, and including, 1.4.103 This is due to the stm_save_user_extra_fields() function updating sensitive user meta fields from POST data without verifying that the current user should have permission to modify those fields. The function hooks into the 'personal_options_update' action and only checks current_user_can('edit_user', $user_id), which passes for any user editing their own profile. This makes it possible for authenticated attackers, with Subscriber-level access and above, to set their stm_payment_status to 'completed', bypassing the PayPal payment verification and gaining access to paid Dealer membership features without completing any transaction. CVE record
CVE-2025-10494, 8 Oct 2025
The Motors - Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation when deleting profile pictures in all versions up to, and including, 1.4.89. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). CVE record
CVE-2025-3437, 8 Apr 2025
The Motors - Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several functions in the ajax_actions.php file in all versions up to, and including, 1.4.66. This makes it possible for authenticated attackers, with Subscriber-level access and above, to execute several initial set-up actions. CVE record
CVE-2025-2808, 8 Apr 2025
The Motors - Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Phone Number parameter in all versions up to, and including, 1.4.63 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2025-2807, 8 Apr 2025
The Motors - Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to arbitrary plugin installations due to a missing capability check in the mvl_setup_wizard_install_plugin() function in all versions up to, and including, 1.4.64. This makes it possible for authenticated attackers, with Subscriber-level access and above, to install and activate arbitrary plugins on the affected site's server which may make remote code execution possible. CVE record
CVE-2024-13737, 22 Mar 2025
The Motors - Car Dealer, Classifieds & Listing plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability checks on the motors_create_template and motors_delete_template functions in all versions up to, and including, 1.4.57. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary posts or create listing templates. This issue requires Elementor plugin to be installed, which is a required plugin for Motors Starter Theme. CVE record
CVE-2024-10970, 16 Jan 2025
The The Motors - Car Dealer, Classifieds & Listing plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.4.43. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for authenticated attackers, with Subscriber-level access and above, to execute arbitrary shortcodes. CVE record
CVE-2022-3989, 12 Dec 2022
The Motors WordPress plugin before 1.4.4 does not properly validate uploaded files for dangerous file types (such as .php) in an AJAX action, allowing an attacker to sign up on a victim's WordPress instance, upload a malicious PHP file and attempt to launch a brute-force attack to discover the uploaded payload. CVE record
CVE-2019-17229, 24 Feb 2020
includes/options.php in the motors-car-dealership-classified-listings (aka Motors - Car Dealer & Classified Ads) plugin through 1.4.0 for WordPress has multiple stored XSS issues. CVE record
CVE-2019-17228, 24 Feb 2020
includes/options.php in the motors-car-dealership-classified-listings (aka Motors - Car Dealer & Classified Ads) plugin through 1.4.0 for WordPress allows unauthenticated options changes. CVE record

What to do if you run Motors

If you run Motors, open WordPress and check the installed version in Plugins. Compare it with the affected versions in the vulnerability record. If a fixed version is available, take a current backup and update to that version or the latest supported release.

If no fixed version exists, consider disabling and removing the plugin or replacing it with a maintained alternative. After dealing with the affected software, check administrator users, unexpected file changes, redirects, unfamiliar pages and security logs for signs that the site may already have been altered.

Email me about new Motors vulnerabilities

Free. We email you when a new vulnerability is published for Motors, usually within minutes. Confirm by email; unsubscribe any time.

Focus on your business. We’ll take care of your website.

From everyday updates to ongoing care, we keep your website working.

Get website support