plugin

Vehica Core Vulnerabilities

5 known security issues reported for the Vehica Core WordPress plugin. Most recent disclosed Aug 11, 2026.

1 high 2 medium

Running Vehica Core on your site? Check whether your installed version is affected.

Scan your site free

Vehica Core <= 1.0.104 - Authenticated (Subscriber+) Server-Side Request Forgery

medium

The Vehica Core plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 1.0.104. This makes it possible for authenticated attackers, with subscriber-level access and above, to make web requests to arbitrary locations originating from the web application which can be used to q...

CVSS:
6.4
Affected:
up to 1.0.104
Fix:
No patched version reported
Disclosed:
Aug 11, 2026

CVE-2026-66654 on NVD →

Vehica Core <= 1.0.100 - Cross-Site Request Forgery

medium

The Vehica Core plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.100. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action granted they can trick a site adminis...

CVSS:
4.3
Affected:
up to 1.0.100
Fixed in:
1.0.101
Disclosed:
Sep 26, 2025

CVE-2025-60117 on NVD →

Vehica Core <= 1.0.97 - Authenticated (Subscriber+) Privilege Escalation

high

The Vehica Core plugin for WordPress, used by the Vehica - Car Dealer & Listing WordPress Theme, is vulnerable to privilege escalation in all versions up to, and including, 1.0.97. This is due to the plugin not properly validating user meta fields prior to updating them in the database. This makes it possible for authe...

CVSS:
8.8
Affected:
up to 1.0.97
Fixed in:
1.0.98
Disclosed:
Apr 3, 2025

CVE-2025-3105 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database