theme

Cardealer Vulnerabilities

7 known security issues reported for the Cardealer WordPress theme. Most recent disclosed Mar 23, 2026.

1 critical 4 high 2 medium

Running Cardealer on your site? Check whether your installed version is affected.

Scan your site free

Car Dealer Automotive WordPress Theme – Responsive <= 1.6.7 - Reflected Cross-Site Scripting

medium

The Car Dealer Automotive WordPress Theme – Responsive theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.6.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages tha...

CVSS:
6.1
Affected:
up to 1.6.7
Fixed in:
1.6.8
Disclosed:
Mar 23, 2026

CVE-2026-24391 on NVD →

Car Dealer < 1.6.7 - Unauthenticated PHP Object Injection

critical

The Car Dealer theme for WordPress is vulnerable to PHP Object Injection in versions up to, and excluding, 1.6.7 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain is present via an...

CVSS:
9.8
Affected:
up to 1.6.7
Fixed in:
1.6.7
Disclosed:
May 22, 2025

CVE-2025-39480 on NVD →

Cardealer <= 1.6.4 - Arbitrary Theme Option Update to Authenticated (Subscriber+) Privilege Escalation

high

The Cardealer theme for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.6.4 due to missing capability check on the 'save_settings' function. This makes it possible for authenticated attackers, with subscriber-level access and above, to modify the default user role.

CVSS:
8.8
Affected:
up to 1.6.4
Fixed in:
1.6.5
Disclosed:
Feb 27, 2025

CVE-2025-1682 on NVD →

Cardealer <= 1.6.4 - Cross-Site Request Forgery to User Update via update_user_profile

high

The Cardealer theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.6.4. This is due to missing nonce validation on the 'update_user_profile' function. This makes it possible for unauthenticated attackers to update the user email and password via a forged request, granted t...

CVSS:
8.8
Affected:
up to 1.6.4
Fixed in:
1.6.5
Disclosed:
Feb 27, 2025

CVE-2025-1687 on NVD →

Cardealer <= 1.6.4 - Missing Authorization to Authenticated (Subscriber+) Change and Delete JS and CSS Files

medium

The Cardealer theme for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check and missing filename sanitization on the demo theme scheme AJAX functions in versions up to, and including, 1.6.4. This makes it possible for authenticated attackers, with subscriber-l...

CVSS:
5.4
Affected:
up to 1.6.4
Fixed in:
1.6.5
Disclosed:
Feb 27, 2025

CVE-2025-1681 on NVD →

Car Dealer Automotive WordPress Theme – Responsive <= 1.6.3 - Authenticated (Subscriber+) Arbitrary File Deletion and Read

high

The Car Dealer Automotive WordPress Theme – Responsive theme for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_post_photo() and add_car() functions in all versions up to, and including, 1.6.3. This makes it possible for authenticated attackers, with Subscriber...

CVSS:
8.8
Affected:
up to 1.6.3
Fixed in:
1.6.4
Disclosed:
Feb 26, 2025

CVE-2025-1282 on NVD →

Car Dealer Automotive WordPress Theme < 1.1.9 - Sensitive Information Disclosure

high

The ThemeMakers Car Dealer / Auto Dealer Responsive theme before 1.1.9 for WordPress allows remote attackers to obtain sensitive information (such as user_login, user_pass, and user_email values) via a direct request for the wp-content/uploads/tmm_db_migrate/wp_users.dat URI.

CVSS:
7.5
Affected:
up to 1.1.9
Fixed in:
1.1.9
Disclosed:
May 15, 2015

CVE-2015-9482 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database