Eklenti güvenlik geçmişi
Motors güvenlik açıkları
ABD Ulusal Güvenlik Açığı Veritabanı’nda (NVD) Motors – Car Dealership & Classified Listings Plugin eklentisi için 30 açık kaydı bulunuyor; en yenisi 6 Ekim 2026 tarihli. Bunların 11 tanesi kritik veya yüksek önemde, 14 tanesi oturum açmadan istismar edilebiliyor. Güncel sürüm 1.4.125.
- Toplam kayıt
- 30
- Kritik veya yüksek
- 11
- Oturumsuz istismar
- 14
- Son kayıt
- 6 Ekim 2026
Bilinen açık kayıtları
En yeniden eskiye. Her kaydın özgün metni NVD’de.
hassas bilgi ifşası
Etkilenen sürümler: 1.4.124 ve öncesi · Oturum açmadan istismar edilebilir
Insertion of Sensitive Information Into Sent Data vulnerability in StylemixThemes Motors allows Retrieve Embedded Sensitive Data. This issue affects Motors: from n/a through 1.4.124.
eksik yetki denetimi
Etkilenen sürümler: 1.4.124 öncesi
The Motors WordPress plugin before 1.4.124 does not properly verify that a user is authorised to modify a listing before processing one of its listing management actions, allowing authenticated attackers with subscriber-level access and above to set metadata on posts they do not own, including overwriting product prices. Exploitation is possible only when WooCommerce is active and the Motors WordPress plugin before 1.4.124's paid featured-listing option is enabled, neither of which is a default configuration.
siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 1.4.124 öncesi
The Motors WordPress plugin before 1.4.124 does not sanitise and escape a listing badge setting before outputting it inside an HTML attribute, allowing users with a custom, administrator-assigned listing-management role to inject arbitrary web scripts that execute when a listing is viewed by any visitor, including an administrator.
SQL enjeksiyonu
Etkilenen sürümler: 1.4.109 ve öncesi · Oturum açmadan istismar edilebilir
WordPress için geliştirilen Motors – Car Dealership & Classified Listings Plugin eklentisi, 1.4.109 sürümüne kadar (bu sürüm dahil) tüm sürümlerinde, kullanıcı tarafından sağlanan parametrede yetersiz kaçış işleme ve mevcut SQL sorgusunda yeterli hazırlık yapılmaması nedeniyle, 'stm_lat/stm_lng' parametresi aracılığıyla zamana dayalı kör SQL enjeksiyonuna karşı savunmasızdır. Bu durum, kimlik doğrulaması yapılmamış saldırganların, veritabanından hassas bilgileri elde etmek için kullanılabilecek ek SQL sorgularını mevcut sorgulara eklemesine olanak tanır.
Türkçe kayıt ve ne yapmalıeksik yetki denetimi
Etkilenen sürümler: 1.4.120 ve öncesi · Oturum açmadan istismar edilebilir
WordPress için geliştirilen “Motors – Car Dealership & Classified Listings Plugin” eklentisi, 1.4.120 sürümüne kadar (bu sürüm dahil) tüm sürümlerinde mvl_ajax_dealer_load_cars() işlevinde yetki denetimlerinin eksik olması nedeniyle, verilere yetkisiz erişim riskine maruz kalmaktadır. Bu durum, kimlik doğrulaması yapılmamış saldırganların, rastgele kullanıcılara ait taslak, beklemede olan, özel ve gelecekteki araç ilanlarını elde etmesine olanak tanır.
yetkisiz nesne erişimi (IDOR)
Etkilenen sürümler: 1.4.121 öncesi · Oturum açmadan istismar edilebilir
1.4.121 sürümünden önceki Motors WordPress eklentisi, bir kullanıcının yayınlanmamış ilanlarını görüntüleme yetkisi olup olmadığını kontrol etmeden bu ilanları döndürmektedir; bu da, kimlik doğrulaması yapılmamış saldırganların herhangi bir yazarın taslak, beklemede olan ve özel araç ilanlarını – başlıklar, fiyatlar, medya URL'leri ve satıcı notları dahil olmak üzere) herhangi bir yazarın taslak, beklemede olan ve özel araç ilanlarını okuyabilmelerine olanak tanır.
eksik yetki denetimi
Etkilenen sürümler: 1.4.113 ve öncesi
Motors'ın <= 1.4.113 sürümlerinde abone erişim denetiminde bir güvenlik açığı bulunmaktadır.
depolanmış siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 1.4.112 ve öncesi · Oturum açmadan istismar edilebilir
The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content and User Biographical Info in all versions up to, and including, 1.4.112 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
eksik yetki denetimi
Etkilenen sürümler: 5.6.80 ve öncesi · Oturum açmadan istismar edilebilir
Unauthenticated Broken Access Control in Motors <= 5.6.80 versions.
eksik yetki denetimi
Etkilenen sürümler: 1.4.111 ve öncesi
The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.4.111. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to mark or unmark any other user's car listing as sold by replaying a valid nonce harvested from their own listing against an arbitrary victim post ID, triggering a site-wide 'Sold' badge on the victim's listing and silently stripping its special_car featured post meta as a side effect. Exploitation requires the attacker to hold an active listing of their own (obtainable by a Subscriber via the plugin's add-listing form) in order to harvest a valid nonce for the 'stm_mark_as_sold_car' action, which can then be replayed against any other listing's post ID.
eksik yetki denetimi
Etkilenen sürümler: 1.4.109 ve öncesi · Oturum açmadan istismar edilebilir
Unauthenticated Broken Access Control in Motors <= 1.4.109 versions.
siteler arası istek sahteciliği (CSRF)
Etkilenen sürümler: 1.4.110 öncesi · Oturum açmadan istismar edilebilir
The Motors WordPress plugin before 1.4.110 does not have proper authorisation and CSRF checks on one of its AJAX actions, allowing unauthenticated attackers to modify arbitrary post metadata, such as the gallery, featured image and, on WooCommerce sites, product prices.
SQL enjeksiyonu
Etkilenen sürümler: 1.4.109 ve öncesi · Oturum açmadan istismar edilebilir
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in StylemixThemes Motors motors-car-dealership-classified-listings allows Blind SQL Injection.This issue affects Motors: from n/a through 1.4.109.
yerel dosya dahil etme (LFI)
Etkilenen sürümler: 1.4.109 ve öncesi · Oturum açmadan istismar edilebilir
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in StylemixThemes Motors allows PHP Local File Inclusion. This issue affects Motors: from n/a through 1.4.109.
eksik yetki denetimi
Etkilenen sürümler: Kayıtta belirtilmemiş
Subscriber Broken Access Control in Motors < 1.4.107 versions.
rastgele dosya silme
Etkilenen sürümler: 1.4.107 ve öncesi
The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including, 1.4.107. This is due to insufficient file path validation in the become-dealer logo upload flow. The plugin allows any authenticated user to set an arbitrary filesystem path via the profile update handler. This makes it possible for authenticated attackers, with subscriber level access and above, to delete arbitrary files on the server.
eksik yetki denetimi
Etkilenen sürümler: 1.4.103 ve öncesi
The Motors – Car Dealership & Classified Listings plugin for WordPress is vulnerable to Payment Bypass via insecure user meta update in all versions up to, and including, 1.4.103 This is due to the stm_save_user_extra_fields() function updating sensitive user meta fields from POST data without verifying that the current user should have permission to modify those fields. The function hooks into the 'personal_options_update' action and only checks current_user_can('edit_user', $user_id), which passes for any user editing their own profile. This makes it possible for authenticated attackers, with Subscriber-level access and above, to set their stm_payment_status to 'completed', bypassing the PayPal payment verification and gaining access to paid Dealer membership features without completing any transaction.
rastgele dosya silme
Etkilenen sürümler: 1.4.89 ve öncesi
The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation when deleting profile pictures in all versions up to, and including, 1.4.89. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).
yetkisiz nesne erişimi (IDOR)
Etkilenen sürümler: 1.4.80 ve öncesi · Oturum açmadan istismar edilebilir
Authorization Bypass Through User-Controlled Key vulnerability in Stylemix Motors motors-car-dealership-classified-listings allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Motors: from n/a through <= 1.4.80.
yerel dosya dahil etme (LFI)
Etkilenen sürümler: 1.4.71 ve öncesi · Oturum açmadan istismar edilebilir
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Stylemix Motors motors-car-dealership-classified-listings allows PHP Local File Inclusion.This issue affects Motors: from n/a through <= 1.4.71.
eksik yetki denetimi
Etkilenen sürümler: 1.4.66 ve öncesi
The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several functions in the ajax_actions.php file in all versions up to, and including, 1.4.66. This makes it possible for authenticated attackers, with Subscriber-level access and above, to execute several initial set-up actions.
depolanmış siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 1.4.63 ve öncesi
The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Phone Number parameter in all versions up to, and including, 1.4.63 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
uzaktan kod çalıştırma
Etkilenen sürümler: 1.4.64 ve öncesi
The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to arbitrary plugin installations due to a missing capability check in the mvl_setup_wizard_install_plugin() function in all versions up to, and including, 1.4.64. This makes it possible for authenticated attackers, with Subscriber-level access and above, to install and activate arbitrary plugins on the affected site's server which may make remote code execution possible.
depolanmış siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 1.4.71 ve öncesi
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Stylemix Motors motors-car-dealership-classified-listings allows Stored XSS.This issue affects Motors: from n/a through <= 1.4.71.
yerel dosya dahil etme (LFI)
Etkilenen sürümler: 1.4.71 ve öncesi
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Stylemix Motors motors-car-dealership-classified-listings allows PHP Local File Inclusion.This issue affects Motors: from n/a through <= 1.4.71.
eksik yetki denetimi
Etkilenen sürümler: 1.4.57 ve öncesi
The Motors – Car Dealer, Classifieds & Listing plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability checks on the motors_create_template and motors_delete_template functions in all versions up to, and including, 1.4.57. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary posts or create listing templates. This issue requires Elementor plugin to be installed, which is a required plugin for Motors Starter Theme.
uzaktan kod çalıştırma
Etkilenen sürümler: 1.4.43 ve öncesi
The The Motors – Car Dealer, Classifieds & Listing plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.4.43. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for authenticated attackers, with Subscriber-level access and above, to execute arbitrary shortcodes.
güvenlik
Etkilenen sürümler: 1.4.4 öncesi
The Motors WordPress plugin before 1.4.4 does not properly validate uploaded files for dangerous file types (such as .php) in an AJAX action, allowing an attacker to sign up on a victim's WordPress instance, upload a malicious PHP file and attempt to launch a brute-force attack to discover the uploaded payload.
depolanmış siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 1.4.0 ve öncesi · Oturum açmadan istismar edilebilir
includes/options.php in the motors-car-dealership-classified-listings (aka Motors - Car Dealer & Classified Ads) plugin through 1.4.0 for WordPress has multiple stored XSS issues.
güvenlik
Etkilenen sürümler: 1.4.0 ve öncesi · Oturum açmadan istismar edilebilir
includes/options.php in the motors-car-dealership-classified-listings (aka Motors - Car Dealer & Classified Ads) plugin through 1.4.0 for WordPress allows unauthenticated options changes.
Kaynak: NVD (kamu malı veri) ve WordPress.org eklenti dizini. Kayıtlar eklentinin WordPress.org adresi veya tam adıyla eşleştirilir. Türkçe açıklamalar makine çevirisidir; bağlayıcı metin NVD’deki İngilizce kayıttır. Veri 7 Ekim 2026 itibarıyla.