theme

Carspot Vulnerabilities

16 known security issues reported for the Carspot WordPress theme. Most recent disclosed Jan 22, 2026.

1 critical 1 high 3 medium

Running Carspot on your site? Check whether your installed version is affected.

Scan your site free

CarSpot [carspot] < 2.4.6

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in scriptsbundle CarSpot carspot allows Reflected XSS.This issue affects CarSpot: from n/a through < 2.4.6.

Affected:
up to 2.4.6
Fixed in:
2.4.6
Disclosed:
Jan 22, 2026

CVE-2025-69317 on NVD →

CarSpot < 2.4.6 - Reflected Cross-Site Scripting

medium

The CarSpot theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to 2.4.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into perfor...

CVSS:
6.1
Affected:
up to 2.4.6
Fixed in:
2.4.6
Disclosed:
Jan 20, 2026

CVE-2025-69317 on NVD →

CarSpot [carspot] < 2.4.4

unknown

[en] The CarSpot – Dealership Wordpress Classified Theme theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 2.4.3. This is due to the plugin not properly validating a token prior to updating a user's password. This makes it possible for unauthenticated a...

Affected:
up to 2.4.4
Fixed in:
2.4.4
Disclosed:
Feb 18, 2025

CVE-2024-12860 on NVD →

CarSpot – Dealership Wordpress Classified Theme <= 2.4.3 - Unauthenticated Arbitrary Password Reset/Account Takeover

critical

The CarSpot – Dealership Wordpress Classified Theme theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 2.4.3. This is due to the plugin not properly validating a token prior to updating a user's password. This makes it possible for unauthenticated attack...

CVSS:
9.8
Affected:
up to 2.4.3
Fixed in:
2.4.4
Disclosed:
Feb 17, 2025

CVE-2024-12860 on NVD →

CarSpot – Dealership Wordpress Classified Theme <= 2.2.3 - Insecure Direct Object Reference

high

The CarSpot – Dealership Wordpress Classified Theme for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 2.2.3 via the 'ad_id' parameter passed via the sb_remove_ad AJAX action. This makes it possible for unauthenticated attackers to delete any posting, page, or ad.

CVSS:
7.5
Affected:
up to 2.2.3
Fixed in:
2.2.4
Disclosed:
Jan 27, 2020

CarSpot – Dealership Wordpress Classified Theme <= 2.2.3 - Stored Cross-Site Scripting

medium

The CarSpot – Dealership Wordpress Classified Theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘admin-ajax.php’ file in versions up to, and including, 2.2.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scri...

CVSS:
6.4
Affected:
up to 2.2.3
Fixed in:
2.2.4
Disclosed:
Jan 27, 2020

CarSpot [carspot] < 2.2.1

unknown

Multiple Vulnerabilities (Authenticated Persistent XSS & IDOR) found by m0ze in WordPress CarSpot theme (versions <= 2.2.0).

Affected:
up to 2.2.1
Fixed in:
2.2.1
Disclosed:
Jan 27, 2020

CarSpot [carspot] < 2.2.3

unknown

Authenticated Persistent Cross-Site Scripting (XSS) vulnerability discovered by m0ze in WordPress CarSpot premium theme (versions <= 2.2.2).

Affected:
up to 2.2.3
Fixed in:
2.2.3
Disclosed:
Jan 27, 2020

CarSpot [carspot] < 2.2.3

unknown

Authenticated Persistent Cross-Site Scripting (XSS) vulnerability (ad post) vulnerability discovered by m0ze in WordPress CarSpot premium theme (versions <= 2.2.2).

Affected:
up to 2.2.3
Fixed in:
2.2.3
Disclosed:
Jan 27, 2020

CarSpot [carspot] < 2.2.3

unknown

Insecure Direct Object References (IDOR) vulnerability discovered by m0ze in WordPress CarSpot premium theme (versions <= 2.2.2).

Affected:
up to 2.2.3
Fixed in:
2.2.3
Disclosed:
Jan 27, 2020

CarSpot [carspot] < 2.2.4

unknown

The CarSpot – Dealership Wordpress Classified Theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘admin-ajax.php’ file in versions up to, and including, 2.2.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scri...

Affected:
up to 2.2.4
Fixed in:
2.2.4
Disclosed:
Jan 27, 2020

CarSpot [carspot] < 2.2.4

unknown

The CarSpot – Dealership Wordpress Classified Theme for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 2.2.3 via the 'ad_id' parameter passed via the sb_remove_ad AJAX action. This makes it possible for unauthenticated attackers to delete any posting, page, or ad.

Affected:
up to 2.2.4
Fixed in:
2.2.4
Disclosed:
Jan 27, 2020

CarSpot [carspot] < 2.1.7

unknown

[en] The CarSpot theme before 2.1.7 for WordPress has stored XSS via the Phone Number field.

Affected:
up to 2.1.7
Fixed in:
2.1.7
Disclosed:
Sep 3, 2019

CVE-2019-15870 on NVD →

CarSpot [carspot] < 2.1.7

unknown

Authenticated Stored Cross-Site Scripting (XSS) vulnerability found by QUIXSS in WordPress CarSpot theme (versions <= 2.1.6).

Affected:
up to 2.1.7
Fixed in:
2.1.7
Disclosed:
Apr 23, 2019

CarSpot – Dealership Wordpress Classified Theme < 2.1.7 - Authenticated Stored Cross-Site Scripting

medium

The CarSpot theme before 2.1.7 for WordPress has stored XSS via the Phone Number field.

CVSS:
6.4
Affected:
up to 2.1.7
Fixed in:
2.1.7
Disclosed:
Apr 18, 2019

CVE-2019-15870 on NVD →

CarSpot [carspot] < 2.2.3

unknown

Multiple vulnerabilities was discovered in the &#039;CarSpot &ndash; Dealership Wordpress Classified Theme&#039;, tested version &mdash; v2.2.0: - Authenticated Persistent XSS -&gt; Registration Form/User Profile - Authenticated Persistent XSS -&gt; Ad Post - IDOR leading to arbitrary deletion of ads Edit (WPSc...

Affected:
up to 2.2.3
Fixed in:
2.2.3

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database