HomeWordPress vulnerabilitiesMotors
Motors vulnerabilities
Motors has 20 known vulnerabilities in this database. The most recent published record is dated 6 Oct 2026.
- Known vulnerabilities
- 20
- Active installs
- 9,000+
- Latest version
- 1.4.124
- Last updated
- 29 Sep 2026
- Most recent
- 6 Oct 2026
No fixed version has been published yet, so consider disabling, removing or replacing the plugin until a safe release is available.
Find it in your WordPress dashboard under Plugins. Severity is based on the CVSS score published with the CVE where one is available.
| Vulnerability | Severity | Affected | Fix | Published |
|---|---|---|---|---|
| Sensitive data exposure CVE-2026-104399 | Medium 6.9 | Up to 1.4.124 | No fixed version yet | 1 d ago |
| Cross-site scripting (XSS) CVE-2026-91022 | Medium 6.8 | Before 1.4.124 | Fixed in 1.4.124 | 5 d ago |
| Broken access control CVE-2026-91023 | Low 3.1 | Before 1.4.124 | Fixed in 1.4.124 | 5 d ago |
| SQL injection CVE-2026-6806 | High 7.5 | Up to 1.4.109 | Fixed in a later version (latest 1.4.124) | 7 d ago |
| Broken access control CVE-2026-16750 | Medium 5.3 | Up to 1.4.120 | Fixed in a later version (latest 1.4.124) | 17 Sep 2026 |
| Broken access control CVE-2026-91016 | Medium 5.3 | Before 1.4.121 | Fixed in 1.4.121 | 17 Sep 2026 |
| Cross-site scripting (XSS) CVE-2026-13114 | High 7.2 | Up to 1.4.112 | Fixed in a later version (latest 1.4.124) | 11 Jul 2026 |
| Broken access control CVE-2026-12435 | Medium 4.3 | Up to 1.4.111 | Fixed in a later version (latest 1.4.124) | 1 Jul 2026 |
| Cross-site request forgery (CSRF) CVE-2026-7859 | Medium 5.3 | Before 1.4.110 | Fixed in 1.4.110 | 22 Jun 2026 |
| Arbitrary file deletion CVE-2026-3892 | High 8.1 | Up to 1.4.107 | Fixed in a later version (latest 1.4.124) | 14 May 2026 |
| Broken access control CVE-2026-1934 | Medium 4.3 | Up to 1.4.103 | Fixed in a later version (latest 1.4.124) | 12 May 2026 |
| Remote code execution CVE-2025-10494 | High 8.1 | Up to 1.4.89 | Fixed in a later version (latest 1.4.124) | 8 Oct 2025 |
| Broken access control CVE-2025-3437 | Medium 4.3 | Before 1.4.67 | Fixed in 1.4.67 | 8 Apr 2025 |
| Cross-site scripting (XSS) CVE-2025-2808 | Medium 5.4 | Before 1.4.64 | Fixed in 1.4.64 | 8 Apr 2025 |
| Remote code execution CVE-2025-2807 | High 8.8 | Before 1.4.65 | Fixed in 1.4.65 | 8 Apr 2025 |
| Broken access control CVE-2024-13737 | Medium 4.3 | Before 1.4.58 | Fixed in 1.4.58 | 22 Mar 2025 |
| Remote code execution CVE-2024-10970 | Medium 5.4 | Before 1.4.44 | Fixed in 1.4.44 | 16 Jan 2025 |
| Security weakness CVE-2022-3989 | High 8.8 | Before 1.4.4 | Fixed in 1.4.4 | 12 Dec 2022 |
| Cross-site scripting (XSS) CVE-2019-17229 | Medium 6.1 | Up to 1.4.0 | Fixed in a later version (latest 1.4.124) | 24 Feb 2020 |
| Security weakness CVE-2019-17228 | Medium 6.5 | Up to 1.4.0 | Fixed in a later version (latest 1.4.124) | 24 Feb 2020 |
Read the published descriptions
- CVE-2026-104399, 6 Oct 2026
- Insertion of Sensitive Information Into Sent Data vulnerability in StylemixThemes Motors allows Retrieve Embedded Sensitive Data. This issue affects Motors: from n/a through 1.4.124. CVE record
- CVE-2026-91022, 2 Oct 2026
- The Motors WordPress plugin before 1.4.124 does not sanitise and escape a listing badge setting before outputting it inside an HTML attribute, allowing users with a custom, administrator-assigned listing-management role to inject arbitrary web scripts that execute when a listing is viewed by any visitor, including an administrator. CVE record
- CVE-2026-91023, 2 Oct 2026
- The Motors WordPress plugin before 1.4.124 does not properly verify that a user is authorised to modify a listing before processing one of its listing management actions, allowing authenticated attackers with subscriber-level access and above to set metadata on posts they do not own, including overwriting product prices. Exploitation is possible only when WooCommerce is active and the Motors WordPress plugin before 1.4.124's paid featured-listing option is enabled, neither of which is a default configuration. CVE record
- CVE-2026-6806, 30 Sep 2026
- The Motors - Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'stm_lat/stm_lng' parameter in all versions up to, and including, 1.4.109 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. CVE record
- CVE-2026-16750, 17 Sep 2026
- The Motors - Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to unauthorized access of data due to missing authorization checks in mvl_ajax_dealer_load_cars() function in all versions up to, and including, 1.4.120. This makes it possible for unauthenticated attackers to retrieve draft, pending, private, and future car listings belonging to arbitrary users. CVE record
- CVE-2026-91016, 17 Sep 2026
- The Motors WordPress plugin before 1.4.121 does not verify that a request is authorized to view a user's non-published listings before returning them, allowing unauthenticated attackers to read any author's draft, pending and private car listings - including titles, prices, media URLs and seller notes - by supplying only the target's numeric user id. CVE record
- CVE-2026-13114, 11 Jul 2026
- The Motors - Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content and User Biographical Info in all versions up to, and including, 1.4.112 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
- CVE-2026-12435, 1 Jul 2026
- The Motors - Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.4.111. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to mark or unmark any other user's car listing as sold by replaying a valid nonce harvested from their own listing against an arbitrary victim post ID, triggering a site-wide 'Sold' badge on the victim's listing and silently stripping its special_car featured post meta as a side effect. Exploitation requires the attacker to hold an active listing of their own (obtainable by a Subscriber via the plugin's add-listing form) in order to harvest a valid nonce for the 'stm_mark_as_sold_car' action, which can then be replayed against any other listing's post ID. CVE record
- CVE-2026-7859, 22 Jun 2026
- The Motors WordPress plugin before 1.4.110 does not have proper authorisation and CSRF checks on one of its AJAX actions, allowing unauthenticated attackers to modify arbitrary post metadata, such as the gallery, featured image and, on WooCommerce sites, product prices. CVE record
- CVE-2026-3892, 14 May 2026
- The Motors - Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including, 1.4.107. This is due to insufficient file path validation in the become-dealer logo upload flow. The plugin allows any authenticated user to set an arbitrary filesystem path via the profile update handler. This makes it possible for authenticated attackers, with subscriber level access and above, to delete arbitrary files on the server. CVE record
- CVE-2026-1934, 12 May 2026
- The Motors - Car Dealership & Classified Listings plugin for WordPress is vulnerable to Payment Bypass via insecure user meta update in all versions up to, and including, 1.4.103 This is due to the stm_save_user_extra_fields() function updating sensitive user meta fields from POST data without verifying that the current user should have permission to modify those fields. The function hooks into the 'personal_options_update' action and only checks current_user_can('edit_user', $user_id), which passes for any user editing their own profile. This makes it possible for authenticated attackers, with Subscriber-level access and above, to set their stm_payment_status to 'completed', bypassing the PayPal payment verification and gaining access to paid Dealer membership features without completing any transaction. CVE record
- CVE-2025-10494, 8 Oct 2025
- The Motors - Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation when deleting profile pictures in all versions up to, and including, 1.4.89. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). CVE record
- CVE-2025-3437, 8 Apr 2025
- The Motors - Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several functions in the ajax_actions.php file in all versions up to, and including, 1.4.66. This makes it possible for authenticated attackers, with Subscriber-level access and above, to execute several initial set-up actions. CVE record
- CVE-2025-2808, 8 Apr 2025
- The Motors - Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Phone Number parameter in all versions up to, and including, 1.4.63 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
- CVE-2025-2807, 8 Apr 2025
- The Motors - Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to arbitrary plugin installations due to a missing capability check in the mvl_setup_wizard_install_plugin() function in all versions up to, and including, 1.4.64. This makes it possible for authenticated attackers, with Subscriber-level access and above, to install and activate arbitrary plugins on the affected site's server which may make remote code execution possible. CVE record
- CVE-2024-13737, 22 Mar 2025
- The Motors - Car Dealer, Classifieds & Listing plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability checks on the motors_create_template and motors_delete_template functions in all versions up to, and including, 1.4.57. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary posts or create listing templates. This issue requires Elementor plugin to be installed, which is a required plugin for Motors Starter Theme. CVE record
- CVE-2024-10970, 16 Jan 2025
- The The Motors - Car Dealer, Classifieds & Listing plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.4.43. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for authenticated attackers, with Subscriber-level access and above, to execute arbitrary shortcodes. CVE record
- CVE-2022-3989, 12 Dec 2022
- The Motors WordPress plugin before 1.4.4 does not properly validate uploaded files for dangerous file types (such as .php) in an AJAX action, allowing an attacker to sign up on a victim's WordPress instance, upload a malicious PHP file and attempt to launch a brute-force attack to discover the uploaded payload. CVE record
- CVE-2019-17229, 24 Feb 2020
- includes/options.php in the motors-car-dealership-classified-listings (aka Motors - Car Dealer & Classified Ads) plugin through 1.4.0 for WordPress has multiple stored XSS issues. CVE record
- CVE-2019-17228, 24 Feb 2020
- includes/options.php in the motors-car-dealership-classified-listings (aka Motors - Car Dealer & Classified Ads) plugin through 1.4.0 for WordPress allows unauthenticated options changes. CVE record
What to do if you run Motors
If you run Motors, open WordPress and check the installed version in Plugins. Compare it with the affected versions in the vulnerability record. If a fixed version is available, take a current backup and update to that version or the latest supported release.
If no fixed version exists, consider disabling and removing the plugin or replacing it with a maintained alternative. After dealing with the affected software, check administrator users, unexpected file changes, redirects, unfamiliar pages and security logs for signs that the site may already have been altered.
Email me about new Motors vulnerabilities
Free. We email you when a new vulnerability is published for Motors, usually within minutes. Confirm by email; unsubscribe any time.
Focus on your business. We’ll take care of your website.
From everyday updates to ongoing care, we keep your website working.