theme

Motors Vulnerabilities

4 known security issues reported for the Motors WordPress theme. Most recent disclosed Jun 30, 2026.

1 critical 2 high 1 medium

Running Motors on your site? Check whether your installed version is affected.

Scan your site free

Motors - Car Dealer, Rental & Listing WordPress theme <= 5.6.80 - Missing Authorization

medium

The Motors - Car Dealer, Rental & Listing WordPress theme theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 5.6.80. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 5.6.80
Fix:
No patched version reported
Disclosed:
Jun 30, 2026

CVE-2026-27433 on NVD →

Motors <= 5.6.82 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Installation

high

The Motors - Car Dealer, Rental & Listing WordPress theme theme for WordPress is vulnerable to unauthorized arbitrary plugin installation due to a missing capability check on the 'mvl_theme_install_base' function in all versions up to, and including, 5.6.82. This makes it possible for authenticated attackers, with Subs...

CVSS:
8.8
Affected:
up to 5.6.82
Fixed in:
5.6.83
Disclosed:
Oct 21, 2025

CVE-2025-64374 on NVD →

Motors <= 5.6.67 - Unauthenticated Privilege Escalation via Password Update/Account Takeover

critical

The Motors theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 5.6.67. This is due to the theme not properly validating a user's identity prior to updating their password. This makes it possible for unauthenticated attackers to change arbitrary user passw...

CVSS:
9.8
Affected:
up to 5.6.67
Fixed in:
5.6.68
Disclosed:
May 19, 2025

CVE-2025-4322 on NVD →

Motors - Car Dealer, Rental & Listing WordPress theme <= 5.6.65 - Unauthenticated Arbitrary Shortcode Execution

high

The The Motors - Car Dealer, Rental & Listing WordPress theme theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.6.65. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes i...

CVSS:
7.3
Affected:
up to 5.6.65
Fixed in:
5.6.66
Disclosed:
May 2, 2025

CVE-2024-13738 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database