WordPress security by component
Motors – Car Dealership & Classified Listings Plugin
Plugin description
Motors – Car Dealership & Classified Listings Plugin is a WordPress component with 18 published CVE records in this archive. The latest tracked vulnerability was published Jul 11, 2026; the highest CVE/CNA score is 9.3.
Plugin slug:
motors-car-dealership-classified-listingsLatest vulnerability
CVE-2026-13114: Motors – Car Dealership & Classified Listings Plugin: Cross-site scripting
Motors – Car Dealership & Classified Listings Plugin is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 1.4.112.
| Safe version |
|
||
|---|---|---|---|
| Jul 11, 2026 |
CVE-2026-13114
Motors – Car Dealership & Classified Listings Plugin: Cross-site scripting
Motors – Car Dealership & Classified Listings Plugin is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 1.4.112.
|
> 1.4.112 |
CVE7.2
NVDPending
|
| Jul 01, 2026 |
CVE-2026-12435
Motors – Car Dealership & Classified Listings Plugin: A security weakness
Motors – Car Dealership & Classified Listings Plugin is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 1.4.111.
|
> 1.4.111 |
CVE4.3
NVDPending
|
| Jun 25, 2026 |
CVE-2026-54828
Motors: A security weakness
Motors is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 1.4.109.
|
1.4.110 |
CVE7.5
NVDPending
|
| Jun 17, 2026 |
CVE-2026-54812
Motors: SQL injection
Motors is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data. The published affected range is n/a through 1.4.109.
|
1.4.110 |
CVE9.3
NVDPending
|
| Jun 17, 2026 |
CVE-2026-54814
Motors: Filesystem traversal
Motors is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server. The published affected range is n/a through 1.4.109.
|
1.4.110 |
CVE8.1
NVDPending
|
| Jun 15, 2026 |
CVE-2026-39515
Motors: A security weakness
Motors is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a to < 1.4.107.
|
1.4.107 |
CVE6.5
NVDPending
|
| May 12, 2026 |
CVE-2026-1934
Motors – Car Dealership & Classified Listings Plugin: A security weakness
Motors – Car Dealership & Classified Listings Plugin is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 1.4.103.
|
> 1.4.103 |
CVE4.3
NVDPending
|
| Aug 14, 2025 |
CVE-2025-54691
Motors: A security weakness
Motors is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Apr 11, 2025 |
CVE-2025-32654
Motors: Filesystem traversal
Motors is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
|
See mitigation notes |
CVE8.1
NVDPending
|
| Apr 04, 2025 |
CVE-2025-32170
Motors: Cross-site scripting
Motors is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Apr 04, 2025 |
CVE-2025-32142
Motors: Filesystem traversal
Motors is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
|
See mitigation notes |
CVE8.8
NVDPending
|
| Mar 22, 2025 |
CVE-2024-13737
Motors – Car Dealer, Classifieds & Listing: A security weakness
Motors – Car Dealer, Classifieds & Listing is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVD4.3
|
| Jan 16, 2025 |
CVE-2024-10970
The Motors – Car Dealer, Classifieds & Listing: A security weakness
The Motors – Car Dealer, Classifieds & Listing is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.4
NVDPending
|
| Nov 13, 2023 |
CVE-2023-46207
Motors – Car Dealer, Classifieds & Listing: Server-side request forgery
Motors – Car Dealer, Classifieds & Listing is affected by server-side request forgery. Exposure depends on how the affected operation is made reachable by the site. The vulnerable server can be induced to make attacker-selected network requests.
|
See mitigation notes |
CVE4.1
NVD7.5
|
| Oct 27, 2023 |
CVE-2023-46208
Motors Car Dealership Classified Listings: Cross-site scripting
Motors Car Dealership Classified Listings is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE7.1
NVD6.1
|
| May 25, 2023 |
CVE-2022-38716
Motors Car Dealership Classified Listings: Cross-site request forgery
Motors Car Dealership Classified Listings is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE5.4
NVD8.8
|
| Feb 24, 2020 |
CVE-2019-17229
Motors Car Dealership Classified Listings: Cross-site scripting
Motors Car Dealership Classified Listings is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVD6.1
|
| Feb 24, 2020 |
CVE-2019-17228
Motors Car Dealership Classified Listings: A security weakness
Motors Car Dealership Classified Listings is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE6.5
NVD6.5
|