Show filters
13 Total Results
Displaying 1-10 of 13
Sort by:
Attacker Value
Unknown

CVE-2024-10970

Disclosure Date: January 16, 2025 (last updated January 16, 2025)
The The Motors – Car Dealer, Classifieds & Listing plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.4.43. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for authenticated attackers, with Subscriber-level access and above, to execute arbitrary shortcodes.
Attacker Value
Unknown

CVE-2024-54298

Disclosure Date: December 13, 2024 (last updated December 18, 2024)
Missing Authorization vulnerability in Bill Minozzi Car Dealer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Car Dealer: from n/a through 4.46.
0
Attacker Value
Unknown

CVE-2024-8259

Disclosure Date: December 09, 2024 (last updated December 18, 2024)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eryaz Information Technologies NatraCar B2B Dealer Management Program allows SQL Injection.This issue affects NatraCar B2B Dealer Management Program: through 09.12.2024. NOTE: The vendor was contacted and it was learned that the product is not supported.
Attacker Value
Unknown

CVE-2024-5545

Disclosure Date: July 02, 2024 (last updated July 06, 2024)
The Motors – Car Dealer, Classifieds & Listing plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the stm_edit_delete_user_car function in all versions up to, and including, 1.4.8. This makes it possible for unauthenticated attackers to unpublish arbitrary posts and pages.
Attacker Value
Unknown

CVE-2024-4214

Disclosure Date: May 17, 2024 (last updated May 17, 2024)
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS vulnerability in Bill Minozzi Car Dealer allows Code Injection.This issue affects Car Dealer: from n/a through 4.15.
0
Attacker Value
Unknown

CVE-2023-46207

Disclosure Date: November 13, 2023 (last updated November 17, 2023)
Server-Side Request Forgery (SSRF) vulnerability in StylemixThemes Motors – Car Dealer, Classifieds & Listing.This issue affects Motors – Car Dealer, Classifieds & Listing: from n/a through 1.4.6.
Attacker Value
Unknown

CVE-2023-46208

Disclosure Date: October 27, 2023 (last updated November 01, 2023)
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in StylemixThemes Motors – Car Dealer, Classifieds & Listing plugin <= 1.4.6 versions.
Attacker Value
Unknown

CVE-2022-38716

Disclosure Date: May 25, 2023 (last updated October 08, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in StylemixThemes Motors – Car Dealer, Classifieds & Listing plugin <= 1.4.4 versions.
Attacker Value
Unknown

CVE-2022-3989

Disclosure Date: December 12, 2022 (last updated October 08, 2023)
The Motors WordPress plugin before 1.4.4 does not properly validate uploaded files for dangerous file types (such as .php) in an AJAX action, allowing an attacker to sign up on a victim's WordPress instance, upload a malicious PHP file and attempt to launch a brute-force attack to discover the uploaded payload.
Attacker Value
Unknown

CVE-2022-3879

Disclosure Date: December 12, 2022 (last updated October 08, 2023)
The Car Dealer (Dealership) and Vehicle sales WordPress Plugin WordPress plugin before 3.05 does not have proper authorisation and CSRF in an AJAX action, allowing any authenticated users, such as subscriber to call it and install and activate arbitrary plugins from wordpress.org