← WordPress Vulnerabilities
WordPress security by component

Motors – Car Dealership & Classified Listings Plugin

Motors – Car Dealership & Classified Listings Plugin is a WordPress component with 18 published CVE records in this archive. The latest tracked vulnerability was published Jul 11, 2026; the highest CVE/CNA score is 9.3.

Plugin slug: motors-car-dealership-classified-listings

CVE-2026-13114: Motors – Car Dealership & Classified Listings Plugin: Cross-site scripting

Motors – Car Dealership & Classified Listings Plugin is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 1.4.112.

PublishedJul 11, 2026
Known safe version> 1.4.112
Safe version
Jul 11, 2026 CVE-2026-13114
Motors – Car Dealership & Classified Listings Plugin: Cross-site scripting
Motors – Car Dealership & Classified Listings Plugin is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 1.4.112.
> 1.4.112
CVE7.2
NVDPending
Jul 01, 2026 CVE-2026-12435
Motors – Car Dealership & Classified Listings Plugin: A security weakness
Motors – Car Dealership & Classified Listings Plugin is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 1.4.111.
> 1.4.111
CVE4.3
NVDPending
Jun 25, 2026 CVE-2026-54828
Motors: A security weakness
Motors is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 1.4.109.
1.4.110
CVE7.5
NVDPending
Jun 17, 2026 CVE-2026-54812
Motors: SQL injection
Motors is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data. The published affected range is n/a through 1.4.109.
1.4.110
CVE9.3
NVDPending
Jun 17, 2026 CVE-2026-54814
Motors: Filesystem traversal
Motors is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server. The published affected range is n/a through 1.4.109.
1.4.110
CVE8.1
NVDPending
Jun 15, 2026 CVE-2026-39515
Motors: A security weakness
Motors is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a to < 1.4.107.
1.4.107
CVE6.5
NVDPending
May 12, 2026 CVE-2026-1934
Motors – Car Dealership & Classified Listings Plugin: A security weakness
Motors – Car Dealership & Classified Listings Plugin is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 1.4.103.
> 1.4.103
CVE4.3
NVDPending
Aug 14, 2025 CVE-2025-54691
Motors: A security weakness
Motors is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Apr 11, 2025 CVE-2025-32654
Motors: Filesystem traversal
Motors is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE8.1
NVDPending
Apr 04, 2025 CVE-2025-32170
Motors: Cross-site scripting
Motors is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVDPending
Apr 04, 2025 CVE-2025-32142
Motors: Filesystem traversal
Motors is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE8.8
NVDPending
Mar 22, 2025 CVE-2024-13737
Motors – Car Dealer, Classifieds & Listing: A security weakness
Motors – Car Dealer, Classifieds & Listing is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVD4.3
Jan 16, 2025 CVE-2024-10970
The Motors – Car Dealer, Classifieds & Listing: A security weakness
The Motors – Car Dealer, Classifieds & Listing is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.4
NVDPending
Nov 13, 2023 CVE-2023-46207
Motors – Car Dealer, Classifieds & Listing: Server-side request forgery
Motors – Car Dealer, Classifieds & Listing is affected by server-side request forgery. Exposure depends on how the affected operation is made reachable by the site. The vulnerable server can be induced to make attacker-selected network requests.
See mitigation notes
CVE4.1
NVD7.5
Oct 27, 2023 CVE-2023-46208
Motors Car Dealership Classified Listings: Cross-site scripting
Motors Car Dealership Classified Listings is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.1
NVD6.1
May 25, 2023 CVE-2022-38716
Motors Car Dealership Classified Listings: Cross-site request forgery
Motors Car Dealership Classified Listings is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE5.4
NVD8.8
Feb 24, 2020 CVE-2019-17229
Motors Car Dealership Classified Listings: Cross-site scripting
Motors Car Dealership Classified Listings is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Feb 24, 2020 CVE-2019-17228
Motors Car Dealership Classified Listings: A security weakness
Motors Car Dealership Classified Listings is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.5
NVD6.5