Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2997▼ 66 respecto a la semana anterior
Críticas / altas1460▲ 109 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
38 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.4) | 0.22% | — | Stylemixthemes Motors - CAR Dealer, Classifieds & Listing | 8/4/2025 | 17/6/2026 | The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Phone Number parameter in all versions up to, and including, 1.4.63 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Analizada | Alta (8.8) | 0.90% | 💥 PoC | Stylemixthemes Motors - CAR Dealer, Classifieds & Listing | 8/4/2025 | 17/6/2026 | The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to arbitrary plugin installations due to a missing capability check in the mvl_setup_wizard_install_plugin() function in all versions up to, and including, 1.4.64. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (6.5) | 0.40% | — | Stylemix MotorsAI | 4/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Stylemix Motors motors-car-dealership-classified-listings allows Stored XSS.This issue affects Motors: from n/a through <= 1.4.71. | |
| Aplazada | Alta (8.8) | 0.77% | — | Stylemix MotorsAI | 4/4/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Stylemix Motors motors-car-dealership-classified-listings allows PHP Local File Inclusion.This issue affects Motors: from n/a through <= 1.4.71. | |
| Analizada | Media (4.3) | 0.30% | — | Stylemixthemes Motors - CAR Dealer, Classifieds & Listing | 22/3/2025 | 17/6/2026 | The Motors – Car Dealer, Classifieds & Listing plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability checks on the motors_create_template and motors_delete_template functions in all versions up to, and including, 1.4.57. This makes it possible for authenticated attackers,… | |
| Analizada | Media (5.4) | 0.33% | — | Stylemixthemes Motors - CAR Dealer, Classifieds & Listing | 16/1/2025 | 17/6/2026 | The The Motors – Car Dealer, Classifieds & Listing plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.4.43. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it… | |
| Modificada | Media (5.3) | 0.33% | — | Stylemixthemes Motors - CAR Dealer, Classifieds & Listing | 2/7/2024 | 17/6/2026 | The Motors – Car Dealer, Classifieds & Listing plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the stm_edit_delete_user_car function in all versions up to, and including, 1.4.8. This makes it possible for unauthenticated attackers to unpublish arbitrary… | |
| Modificada | Alta (7.5) | 0.51% | — | Stylemixthemes Motors - CAR Dealer, Classifieds & Listing | 13/11/2023 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in StylemixThemes Motors – Car Dealer, Classifieds & Listing.This issue affects Motors – Car Dealer, Classifieds & Listing: from n/a through 1.4.6. | |
| Modificada | Media (6.1) | 0.33% | — | Stylemixthemes Motors - CAR Dealer, Classifieds & Listing | 27/10/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in StylemixThemes Motors – Car Dealer, Classifieds & Listing plugin <= 1.4.6 versions. | |
| Modificada | Alta (8.8) | 0.25% | — | Stylemixthemes Motors - CAR Dealer, Classifieds & Listing | 25/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in StylemixThemes Motors – Car Dealer, Classifieds & Listing plugin <= 1.4.4 versions. | |
| Modificada | Alta (8.8) | 1.1% | — | Stylemixthemes Motors - CAR Dealer, Classifieds & Listing | 12/12/2022 | 17/6/2026 | The Motors WordPress plugin before 1.4.4 does not properly validate uploaded files for dangerous file types (such as .php) in an AJAX action, allowing an attacker to sign up on a victim's WordPress instance, upload a malicious PHP file and attempt to launch a brute-force attack to discover the uploaded payload. | |
| Modificada | Media (6.1) | 1.4% | — | Stylemixthemes Motors - CAR Dealer, Classifieds & Listing | 24/2/2020 | 17/6/2026 | includes/options.php in the motors-car-dealership-classified-listings (aka Motors - Car Dealer & Classified Ads) plugin through 1.4.0 for WordPress has multiple stored XSS issues. | |
| Modificada | Media (6.5) | 1.2% | 💥 Exploit | Stylemixthemes Motors - CAR Dealer, Classifieds & Listing | 24/2/2020 | 17/6/2026 | includes/options.php in the motors-car-dealership-classified-listings (aka Motors - Car Dealer & Classified Ads) plugin through 1.4.0 for WordPress allows unauthenticated options changes. |