WPHizmet

Eklenti güvenlik geçmişi

Motors güvenlik açıkları

ABD Ulusal Güvenlik Açığı Veritabanı’nda (NVD) Motors – Car Dealership & Classified Listings Plugin eklentisi için 30 açık kaydı bulunuyor; en yenisi 6 Ekim 2026 tarihli. Bunların 11 tanesi kritik veya yüksek önemde, 14 tanesi oturum açmadan istismar edilebiliyor. Güncel sürüm 1.4.125.

Toplam kayıt
30
Kritik veya yüksek
11
Oturumsuz istismar
14
Son kayıt
6 Ekim 2026

Bilinen açık kayıtları

En yeniden eskiye. Her kaydın özgün metni NVD’de.

  • CVE-2026-104399Orta · 6,96 Ekim 2026

    hassas bilgi ifşası

    Etkilenen sürümler: 1.4.124 ve öncesi · Oturum açmadan istismar edilebilir

    Insertion of Sensitive Information Into Sent Data vulnerability in StylemixThemes Motors allows Retrieve Embedded Sensitive Data. This issue affects Motors: from n/a through 1.4.124.

  • CVE-2026-91023Düşük · 3,12 Ekim 2026

    eksik yetki denetimi

    Etkilenen sürümler: 1.4.124 öncesi

    The Motors WordPress plugin before 1.4.124 does not properly verify that a user is authorised to modify a listing before processing one of its listing management actions, allowing authenticated attackers with subscriber-level access and above to set metadata on posts they do not own, including overwriting product prices. Exploitation is possible only when WooCommerce is active and the Motors WordPress plugin before 1.4.124's paid featured-listing option is enabled, neither of which is a default configuration.

  • CVE-2026-91022Orta · 6,82 Ekim 2026

    siteler arası betik çalıştırma (XSS)

    Etkilenen sürümler: 1.4.124 öncesi

    The Motors WordPress plugin before 1.4.124 does not sanitise and escape a listing badge setting before outputting it inside an HTML attribute, allowing users with a custom, administrator-assigned listing-management role to inject arbitrary web scripts that execute when a listing is viewed by any visitor, including an administrator.

  • CVE-2026-6806Yüksek · 7,530 Eylül 2026

    SQL enjeksiyonu

    Etkilenen sürümler: 1.4.109 ve öncesi · Oturum açmadan istismar edilebilir

    WordPress için geliştirilen Motors – Car Dealership & Classified Listings Plugin eklentisi, 1.4.109 sürümüne kadar (bu sürüm dahil) tüm sürümlerinde, kullanıcı tarafından sağlanan parametrede yetersiz kaçış işleme ve mevcut SQL sorgusunda yeterli hazırlık yapılmaması nedeniyle, 'stm_lat/stm_lng' parametresi aracılığıyla zamana dayalı kör SQL enjeksiyonuna karşı savunmasızdır. Bu durum, kimlik doğrulaması yapılmamış saldırganların, veritabanından hassas bilgileri elde etmek için kullanılabilecek ek SQL sorgularını mevcut sorgulara eklemesine olanak tanır.

    Türkçe kayıt ve ne yapmalı
  • CVE-2026-16750Orta · 5,318 Eylül 2026

    eksik yetki denetimi

    Etkilenen sürümler: 1.4.120 ve öncesi · Oturum açmadan istismar edilebilir

    WordPress için geliştirilen “Motors – Car Dealership & Classified Listings Plugin” eklentisi, 1.4.120 sürümüne kadar (bu sürüm dahil) tüm sürümlerinde mvl_ajax_dealer_load_cars() işlevinde yetki denetimlerinin eksik olması nedeniyle, verilere yetkisiz erişim riskine maruz kalmaktadır. Bu durum, kimlik doğrulaması yapılmamış saldırganların, rastgele kullanıcılara ait taslak, beklemede olan, özel ve gelecekteki araç ilanlarını elde etmesine olanak tanır.

  • CVE-2026-91016Orta · 5,317 Eylül 2026

    yetkisiz nesne erişimi (IDOR)

    Etkilenen sürümler: 1.4.121 öncesi · Oturum açmadan istismar edilebilir

    1.4.121 sürümünden önceki Motors WordPress eklentisi, bir kullanıcının yayınlanmamış ilanlarını görüntüleme yetkisi olup olmadığını kontrol etmeden bu ilanları döndürmektedir; bu da, kimlik doğrulaması yapılmamış saldırganların herhangi bir yazarın taslak, beklemede olan ve özel araç ilanlarını – başlıklar, fiyatlar, medya URL'leri ve satıcı notları dahil olmak üzere) herhangi bir yazarın taslak, beklemede olan ve özel araç ilanlarını okuyabilmelerine olanak tanır.

  • CVE-2026-66693Orta · 6,513 Ağustos 2026

    eksik yetki denetimi

    Etkilenen sürümler: 1.4.113 ve öncesi

    Motors'ın <= 1.4.113 sürümlerinde abone erişim denetiminde bir güvenlik açığı bulunmaktadır.

  • CVE-2026-13114Yüksek · 7,211 Temmuz 2026

    depolanmış siteler arası betik çalıştırma (XSS)

    Etkilenen sürümler: 1.4.112 ve öncesi · Oturum açmadan istismar edilebilir

    The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content and User Biographical Info in all versions up to, and including, 1.4.112 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

  • CVE-2026-27433Orta · 6,52 Temmuz 2026

    eksik yetki denetimi

    Etkilenen sürümler: 5.6.80 ve öncesi · Oturum açmadan istismar edilebilir

    Unauthenticated Broken Access Control in Motors <= 5.6.80 versions.

  • CVE-2026-12435Orta · 4,31 Temmuz 2026

    eksik yetki denetimi

    Etkilenen sürümler: 1.4.111 ve öncesi

    The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.4.111. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to mark or unmark any other user's car listing as sold by replaying a valid nonce harvested from their own listing against an arbitrary victim post ID, triggering a site-wide 'Sold' badge on the victim's listing and silently stripping its special_car featured post meta as a side effect. Exploitation requires the attacker to hold an active listing of their own (obtainable by a Subscriber via the plugin's add-listing form) in order to harvest a valid nonce for the 'stm_mark_as_sold_car' action, which can then be replayed against any other listing's post ID.

  • CVE-2026-54828Yüksek · 7,525 Haziran 2026

    eksik yetki denetimi

    Etkilenen sürümler: 1.4.109 ve öncesi · Oturum açmadan istismar edilebilir

    Unauthenticated Broken Access Control in Motors <= 1.4.109 versions.

  • CVE-2026-7859Orta · 5,322 Haziran 2026

    siteler arası istek sahteciliği (CSRF)

    Etkilenen sürümler: 1.4.110 öncesi · Oturum açmadan istismar edilebilir

    The Motors WordPress plugin before 1.4.110 does not have proper authorisation and CSRF checks on one of its AJAX actions, allowing unauthenticated attackers to modify arbitrary post metadata, such as the gallery, featured image and, on WooCommerce sites, product prices.

  • CVE-2026-54812Kritik · 9,317 Haziran 2026

    SQL enjeksiyonu

    Etkilenen sürümler: 1.4.109 ve öncesi · Oturum açmadan istismar edilebilir

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in StylemixThemes Motors motors-car-dealership-classified-listings allows Blind SQL Injection.This issue affects Motors: from n/a through 1.4.109.

  • CVE-2026-54814Yüksek · 8,117 Haziran 2026

    yerel dosya dahil etme (LFI)

    Etkilenen sürümler: 1.4.109 ve öncesi · Oturum açmadan istismar edilebilir

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in StylemixThemes Motors allows PHP Local File Inclusion. This issue affects Motors: from n/a through 1.4.109.

  • CVE-2026-39515Orta · 6,516 Haziran 2026

    eksik yetki denetimi

    Etkilenen sürümler: Kayıtta belirtilmemiş

    Subscriber Broken Access Control in Motors < 1.4.107 versions.

  • CVE-2026-3892Yüksek · 8,114 Mayıs 2026

    rastgele dosya silme

    Etkilenen sürümler: 1.4.107 ve öncesi

    The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including, 1.4.107. This is due to insufficient file path validation in the become-dealer logo upload flow. The plugin allows any authenticated user to set an arbitrary filesystem path via the profile update handler. This makes it possible for authenticated attackers, with subscriber level access and above, to delete arbitrary files on the server.

  • CVE-2026-1934Orta · 4,312 Mayıs 2026

    eksik yetki denetimi

    Etkilenen sürümler: 1.4.103 ve öncesi

    The Motors – Car Dealership & Classified Listings plugin for WordPress is vulnerable to Payment Bypass via insecure user meta update in all versions up to, and including, 1.4.103 This is due to the stm_save_user_extra_fields() function updating sensitive user meta fields from POST data without verifying that the current user should have permission to modify those fields. The function hooks into the 'personal_options_update' action and only checks current_user_can('edit_user', $user_id), which passes for any user editing their own profile. This makes it possible for authenticated attackers, with Subscriber-level access and above, to set their stm_payment_status to 'completed', bypassing the PayPal payment verification and gaining access to paid Dealer membership features without completing any transaction.

  • CVE-2025-10494Yüksek · 8,18 Ekim 2025

    rastgele dosya silme

    Etkilenen sürümler: 1.4.89 ve öncesi

    The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation when deleting profile pictures in all versions up to, and including, 1.4.89. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).

  • CVE-2025-54691Orta · 5,314 Ağustos 2025

    yetkisiz nesne erişimi (IDOR)

    Etkilenen sürümler: 1.4.80 ve öncesi · Oturum açmadan istismar edilebilir

    Authorization Bypass Through User-Controlled Key vulnerability in Stylemix Motors motors-car-dealership-classified-listings allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Motors: from n/a through <= 1.4.80.

  • CVE-2025-32654Yüksek · 8,111 Nisan 2025

    yerel dosya dahil etme (LFI)

    Etkilenen sürümler: 1.4.71 ve öncesi · Oturum açmadan istismar edilebilir

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Stylemix Motors motors-car-dealership-classified-listings allows PHP Local File Inclusion.This issue affects Motors: from n/a through <= 1.4.71.

  • CVE-2025-3437Orta · 4,38 Nisan 2025

    eksik yetki denetimi

    Etkilenen sürümler: 1.4.66 ve öncesi

    The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several functions in the ajax_actions.php file in all versions up to, and including, 1.4.66. This makes it possible for authenticated attackers, with Subscriber-level access and above, to execute several initial set-up actions.

  • CVE-2025-2808Orta · 5,48 Nisan 2025

    depolanmış siteler arası betik çalıştırma (XSS)

    Etkilenen sürümler: 1.4.63 ve öncesi

    The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Phone Number parameter in all versions up to, and including, 1.4.63 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

  • CVE-2025-2807Yüksek · 8,88 Nisan 2025

    uzaktan kod çalıştırma

    Etkilenen sürümler: 1.4.64 ve öncesi

    The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to arbitrary plugin installations due to a missing capability check in the mvl_setup_wizard_install_plugin() function in all versions up to, and including, 1.4.64. This makes it possible for authenticated attackers, with Subscriber-level access and above, to install and activate arbitrary plugins on the affected site's server which may make remote code execution possible.

  • CVE-2025-32170Orta · 6,54 Nisan 2025

    depolanmış siteler arası betik çalıştırma (XSS)

    Etkilenen sürümler: 1.4.71 ve öncesi

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Stylemix Motors motors-car-dealership-classified-listings allows Stored XSS.This issue affects Motors: from n/a through <= 1.4.71.

  • CVE-2025-32142Yüksek · 8,84 Nisan 2025

    yerel dosya dahil etme (LFI)

    Etkilenen sürümler: 1.4.71 ve öncesi

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Stylemix Motors motors-car-dealership-classified-listings allows PHP Local File Inclusion.This issue affects Motors: from n/a through <= 1.4.71.

  • CVE-2024-13737Orta · 4,322 Mart 2025

    eksik yetki denetimi

    Etkilenen sürümler: 1.4.57 ve öncesi

    The Motors – Car Dealer, Classifieds & Listing plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability checks on the motors_create_template and motors_delete_template functions in all versions up to, and including, 1.4.57. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary posts or create listing templates. This issue requires Elementor plugin to be installed, which is a required plugin for Motors Starter Theme.

  • CVE-2024-10970Orta · 5,416 Ocak 2025

    uzaktan kod çalıştırma

    Etkilenen sürümler: 1.4.43 ve öncesi

    The The Motors – Car Dealer, Classifieds & Listing plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.4.43. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for authenticated attackers, with Subscriber-level access and above, to execute arbitrary shortcodes.

  • CVE-2022-3989Yüksek · 8,812 Aralık 2022

    güvenlik

    Etkilenen sürümler: 1.4.4 öncesi

    The Motors WordPress plugin before 1.4.4 does not properly validate uploaded files for dangerous file types (such as .php) in an AJAX action, allowing an attacker to sign up on a victim's WordPress instance, upload a malicious PHP file and attempt to launch a brute-force attack to discover the uploaded payload.

  • CVE-2019-17229Orta · 6,124 Şubat 2020

    depolanmış siteler arası betik çalıştırma (XSS)

    Etkilenen sürümler: 1.4.0 ve öncesi · Oturum açmadan istismar edilebilir

    includes/options.php in the motors-car-dealership-classified-listings (aka Motors - Car Dealer & Classified Ads) plugin through 1.4.0 for WordPress has multiple stored XSS issues.

  • CVE-2019-17228Orta · 6,524 Şubat 2020

    güvenlik

    Etkilenen sürümler: 1.4.0 ve öncesi · Oturum açmadan istismar edilebilir

    includes/options.php in the motors-car-dealership-classified-listings (aka Motors - Car Dealer & Classified Ads) plugin through 1.4.0 for WordPress allows unauthenticated options changes.

Kaynak: NVD (kamu malı veri) ve WordPress.org eklenti dizini. Kayıtlar eklentinin WordPress.org adresi veya tam adıyla eşleştirilir. Türkçe açıklamalar makine çevirisidir; bağlayıcı metin NVD’deki İngilizce kayıttır. Veri 7 Ekim 2026 itibarıyla.