CarZone - A Complete Car Dealer HTML Wire-Frame <= 3.7 - Unauthenticated Arbitrary File Deletion
critical
The CarZone - A Complete Car Dealer HTML Wire-Frame theme for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in all versions up to, and including, 3.7. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remo...
- CVSS:
- 9.1
- Affected:
- up to 3.7
- Fix:
- No patched version reported
- Disclosed:
- May 26, 2026
CVE-2025-69139 on NVD →
Car Zone <= 3.7 - Authenticated (Subscriber+) PHP Object Injection
high
The CarZone - A Complete Car Dealer HTML Wire-Frame theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.7 via deserialization of untrusted input. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject a PHP Object. No known POP...
- CVSS:
- 7.5
- Affected:
- up to 3.7
- Fix:
- No patched version reported
- Disclosed:
- Mar 3, 2026
CVE-2026-27338 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database