CarSpot [carspot] < 2.4.6
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in scriptsbundle CarSpot carspot allows Reflected XSS.This issue affects CarSpot: from n/a through < 2.4.6.
- Affected:
- up to 2.4.6
- Fixed in:
- 2.4.6
- Disclosed:
- Jan 22, 2026
CVE-2025-69317 on NVD →
CarSpot < 2.4.6 - Reflected Cross-Site Scripting
medium
The CarSpot theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to 2.4.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into perfor...
- CVSS:
- 6.1
- Affected:
- up to 2.4.6
- Fixed in:
- 2.4.6
- Disclosed:
- Jan 20, 2026
CVE-2025-69317 on NVD →
CarSpot [carspot] < 2.4.4
unknown
[en] The CarSpot – Dealership Wordpress Classified Theme theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 2.4.3. This is due to the plugin not properly validating a token prior to updating a user's password. This makes it possible for unauthenticated a...
- Affected:
- up to 2.4.4
- Fixed in:
- 2.4.4
- Disclosed:
- Feb 18, 2025
CVE-2024-12860 on NVD →
CarSpot – Dealership Wordpress Classified Theme <= 2.4.3 - Unauthenticated Arbitrary Password Reset/Account Takeover
critical
The CarSpot – Dealership Wordpress Classified Theme theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 2.4.3. This is due to the plugin not properly validating a token prior to updating a user's password. This makes it possible for unauthenticated attack...
- CVSS:
- 9.8
- Affected:
- up to 2.4.3
- Fixed in:
- 2.4.4
- Disclosed:
- Feb 17, 2025
CVE-2024-12860 on NVD →
CarSpot – Dealership Wordpress Classified Theme <= 2.2.3 - Insecure Direct Object Reference
high
The CarSpot – Dealership Wordpress Classified Theme for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 2.2.3 via the 'ad_id' parameter passed via the sb_remove_ad AJAX action. This makes it possible for unauthenticated attackers to delete any posting, page, or ad.
- CVSS:
- 7.5
- Affected:
- up to 2.2.3
- Fixed in:
- 2.2.4
- Disclosed:
- Jan 27, 2020
CarSpot – Dealership Wordpress Classified Theme <= 2.2.3 - Stored Cross-Site Scripting
medium
The CarSpot – Dealership Wordpress Classified Theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘admin-ajax.php’ file in versions up to, and including, 2.2.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scri...
- CVSS:
- 6.4
- Affected:
- up to 2.2.3
- Fixed in:
- 2.2.4
- Disclosed:
- Jan 27, 2020
CarSpot [carspot] < 2.2.1
unknown
Multiple Vulnerabilities (Authenticated Persistent XSS & IDOR) found by m0ze in WordPress CarSpot theme (versions <= 2.2.0).
- Affected:
- up to 2.2.1
- Fixed in:
- 2.2.1
- Disclosed:
- Jan 27, 2020
CarSpot [carspot] < 2.2.3
unknown
Authenticated Persistent Cross-Site Scripting (XSS) vulnerability discovered by m0ze in WordPress CarSpot premium theme (versions <= 2.2.2).
- Affected:
- up to 2.2.3
- Fixed in:
- 2.2.3
- Disclosed:
- Jan 27, 2020
CarSpot [carspot] < 2.2.3
unknown
Authenticated Persistent Cross-Site Scripting (XSS) vulnerability (ad post) vulnerability discovered by m0ze in WordPress CarSpot premium theme (versions <= 2.2.2).
- Affected:
- up to 2.2.3
- Fixed in:
- 2.2.3
- Disclosed:
- Jan 27, 2020
CarSpot [carspot] < 2.2.3
unknown
Insecure Direct Object References (IDOR) vulnerability discovered by m0ze in WordPress CarSpot premium theme (versions <= 2.2.2).
- Affected:
- up to 2.2.3
- Fixed in:
- 2.2.3
- Disclosed:
- Jan 27, 2020
CarSpot [carspot] < 2.2.4
unknown
The CarSpot – Dealership Wordpress Classified Theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘admin-ajax.php’ file in versions up to, and including, 2.2.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scri...
- Affected:
- up to 2.2.4
- Fixed in:
- 2.2.4
- Disclosed:
- Jan 27, 2020
CarSpot [carspot] < 2.2.4
unknown
The CarSpot – Dealership Wordpress Classified Theme for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 2.2.3 via the 'ad_id' parameter passed via the sb_remove_ad AJAX action. This makes it possible for unauthenticated attackers to delete any posting, page, or ad.
- Affected:
- up to 2.2.4
- Fixed in:
- 2.2.4
- Disclosed:
- Jan 27, 2020
CarSpot [carspot] < 2.1.7
unknown
[en] The CarSpot theme before 2.1.7 for WordPress has stored XSS via the Phone Number field.
- Affected:
- up to 2.1.7
- Fixed in:
- 2.1.7
- Disclosed:
- Sep 3, 2019
CVE-2019-15870 on NVD →
CarSpot [carspot] < 2.1.7
unknown
Authenticated Stored Cross-Site Scripting (XSS) vulnerability found by QUIXSS in WordPress CarSpot theme (versions <= 2.1.6).
- Affected:
- up to 2.1.7
- Fixed in:
- 2.1.7
- Disclosed:
- Apr 23, 2019
CarSpot – Dealership Wordpress Classified Theme < 2.1.7 - Authenticated Stored Cross-Site Scripting
medium
The CarSpot theme before 2.1.7 for WordPress has stored XSS via the Phone Number field.
- CVSS:
- 6.4
- Affected:
- up to 2.1.7
- Fixed in:
- 2.1.7
- Disclosed:
- Apr 18, 2019
CVE-2019-15870 on NVD →
CarSpot [carspot] < 2.2.3
unknown
Multiple vulnerabilities was discovered in the 'CarSpot – Dealership Wordpress Classified Theme', tested version — v2.2.0:
- Authenticated Persistent XSS -> Registration Form/User Profile
- Authenticated Persistent XSS -> Ad Post
- IDOR leading to arbitrary deletion of ads
Edit (WPSc...
- Affected:
- up to 2.2.3
- Fixed in:
- 2.2.3
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database