Car Dealer Automotive WordPress Theme – Responsive <= 1.6.7 - Reflected Cross-Site Scripting
medium
The Car Dealer Automotive WordPress Theme – Responsive theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.6.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages tha...
- CVSS:
- 6.1
- Affected:
- up to 1.6.7
- Fixed in:
- 1.6.8
- Disclosed:
- Mar 23, 2026
CVE-2026-24391 on NVD →
Car Dealer < 1.6.7 - Unauthenticated PHP Object Injection
critical
The Car Dealer theme for WordPress is vulnerable to PHP Object Injection in versions up to, and excluding, 1.6.7 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain is present via an...
- CVSS:
- 9.8
- Affected:
- up to 1.6.7
- Fixed in:
- 1.6.7
- Disclosed:
- May 22, 2025
CVE-2025-39480 on NVD →
Cardealer <= 1.6.4 - Arbitrary Theme Option Update to Authenticated (Subscriber+) Privilege Escalation
high
The Cardealer theme for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.6.4 due to missing capability check on the 'save_settings' function. This makes it possible for authenticated attackers, with subscriber-level access and above, to modify the default user role.
- CVSS:
- 8.8
- Affected:
- up to 1.6.4
- Fixed in:
- 1.6.5
- Disclosed:
- Feb 27, 2025
CVE-2025-1682 on NVD →
Cardealer <= 1.6.4 - Cross-Site Request Forgery to User Update via update_user_profile
high
The Cardealer theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.6.4. This is due to missing nonce validation on the 'update_user_profile' function. This makes it possible for unauthenticated attackers to update the user email and password via a forged request, granted t...
- CVSS:
- 8.8
- Affected:
- up to 1.6.4
- Fixed in:
- 1.6.5
- Disclosed:
- Feb 27, 2025
CVE-2025-1687 on NVD →
Cardealer <= 1.6.4 - Missing Authorization to Authenticated (Subscriber+) Change and Delete JS and CSS Files
medium
The Cardealer theme for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check and missing filename sanitization on the demo theme scheme AJAX functions in versions up to, and including, 1.6.4. This makes it possible for authenticated attackers, with subscriber-l...
- CVSS:
- 5.4
- Affected:
- up to 1.6.4
- Fixed in:
- 1.6.5
- Disclosed:
- Feb 27, 2025
CVE-2025-1681 on NVD →
Car Dealer Automotive WordPress Theme – Responsive <= 1.6.3 - Authenticated (Subscriber+) Arbitrary File Deletion and Read
high
The Car Dealer Automotive WordPress Theme – Responsive theme for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_post_photo() and add_car() functions in all versions up to, and including, 1.6.3. This makes it possible for authenticated attackers, with Subscriber...
- CVSS:
- 8.8
- Affected:
- up to 1.6.3
- Fixed in:
- 1.6.4
- Disclosed:
- Feb 26, 2025
CVE-2025-1282 on NVD →
Car Dealer Automotive WordPress Theme < 1.1.9 - Sensitive Information Disclosure
high
The ThemeMakers Car Dealer / Auto Dealer Responsive theme before 1.1.9 for WordPress allows remote attackers to obtain sensitive information (such as user_login, user_pass, and user_email values) via a direct request for the wp-content/uploads/tmm_db_migrate/wp_users.dat URI.
- CVSS:
- 7.5
- Affected:
- up to 1.1.9
- Fixed in:
- 1.1.9
- Disclosed:
- May 15, 2015
CVE-2015-9482 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database