Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2811▼ 173 respecto a la semana anterior
Críticas / altas1356▲ 48 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)267▼ 256 respecto a la semana anterior
38 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Media (6.9) | 0.41% | — | Stylemixthemes MotorsAI | 6/10/2026 | 6/10/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in StylemixThemes Motors allows Retrieve Embedded Sensitive Data. This issue affects Motors: from n/a through 1.4.124. | |
| Aplazada | Baja (3.1) | 0.13% | — | MotorsAI | 2/10/2026 | 2/10/2026 | The Motors WordPress plugin before 1.4.124 does not properly verify that a user is authorised to modify a listing before processing one of its listing management actions, allowing authenticated attackers with subscriber-level access and above to set metadata on posts they do not own, including overwriting product… | |
| Aplazada | Media (6.8) | 0.24% | — | MotorsAI | 2/10/2026 | 2/10/2026 | The Motors WordPress plugin before 1.4.124 does not sanitise and escape a listing badge setting before outputting it inside an HTML attribute, allowing users with a custom, administrator-assigned listing-management role to inject arbitrary web scripts that execute when a listing is viewed by any visitor, including an… | |
| Aplazada | Alta (7.5) | 0.27% | — | MotorsAI | 30/9/2026 | 30/9/2026 | The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'stm_lat/stm_lng' parameter in all versions up to, and including, 1.4.109 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing… | |
| Aplazada | Media (5.3) | 0.24% | — | MotorsAI | 17/9/2026 | 18/9/2026 | The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to unauthorized access of data due to missing authorization checks in mvl_ajax_dealer_load_cars() function in all versions up to, and including, 1.4.120. This makes it possible for unauthenticated attackers to retrieve draft,… | |
| Aplazada | Media (5.3) | 0.32% | — | MotorsAI | 17/9/2026 | 18/9/2026 | The Motors WordPress plugin before 1.4.121 does not verify that a request is authorized to view a user's non-published listings before returning them, allowing unauthenticated attackers to read any author's draft, pending and private car listings - including titles, prices, media URLs and seller notes - by supplying… | |
| Aplazada | Media (6.5) | 0.30% | — | MotorsAI | 13/8/2026 | 14/8/2026 | Subscriber Broken Access Control in Motors <= 1.4.113 versions. | |
| Aplazada | Alta (7.2) | 0.43% | — | MotorsAI | 11/7/2026 | 13/7/2026 | The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content and User Biographical Info in all versions up to, and including, 1.4.112 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated… | |
| Aplazada | Media (6.5) | 0.33% | — | MotorsAI | 2/7/2026 | 2/7/2026 | Unauthenticated Broken Access Control in Motors <= 5.6.80 versions. | |
| Aplazada | Media (4.3) | 0.40% | — | MotorsAI | 1/7/2026 | 1/7/2026 | The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.4.111. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with… | |
| Aplazada | Alta (7.5) | 0.35% | — | MotorsAI | 25/6/2026 | 25/6/2026 | Unauthenticated Broken Access Control in Motors <= 1.4.109 versions. | |
| Aplazada | Media (5.3) | 0.16% | — | MotorsAI | 22/6/2026 | 22/6/2026 | The Motors WordPress plugin before 1.4.110 does not have proper authorisation and CSRF checks on one of its AJAX actions, allowing unauthenticated attackers to modify arbitrary post metadata, such as the gallery, featured image and, on WooCommerce sites, product prices. | |
| Aplazada | Alta (8.1) | 0.56% | — | Stylemixthemes MotorsAI | 17/6/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in StylemixThemes Motors allows PHP Local File Inclusion. This issue affects Motors: from n/a through 1.4.109. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Stylemixthemes MotorsAI | 17/6/2026 | 30/9/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in StylemixThemes Motors motors-car-dealership-classified-listings allows Blind SQL Injection.This issue affects Motors: from n/a through 1.4.109. | |
| Aplazada | Media (6.5) | 0.37% | — | MotorsAI | 15/6/2026 | 17/6/2026 | Subscriber Broken Access Control in Motors < 1.4.107 versions. | |
| Aplazada | Alta (8.1) | 0.46% | — | Wptools MotorsAI | 14/5/2026 | 17/6/2026 | The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including, 1.4.107. This is due to insufficient file path validation in the become-dealer logo upload flow. The plugin allows any authenticated user to set an arbitrary… | |
| Aplazada | Media (4.3) | 0.22% | — | MotorsAI | 12/5/2026 | 17/6/2026 | The Motors – Car Dealership & Classified Listings plugin for WordPress is vulnerable to Payment Bypass via insecure user meta update in all versions up to, and including, 1.4.103 This is due to the stm_save_user_extra_fields() function updating sensitive user meta fields from POST data without verifying that the… | |
| Aplazada | Crítica (9.9) | 0.36% | — | Stylemixthemes MotorsAI | 18/12/2025 | 5/10/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in StylemixThemes Motors motors allows Using Malicious Files.This issue affects Motors: from n/a through <= 5.6.81. | |
| Aplazada | Alta (8.1) | 0.49% | — | MotorsAI | 8/10/2025 | 17/6/2026 | The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation when deleting profile pictures in all versions up to, and including, 1.4.89. This makes it possible for authenticated attackers, with Subscriber-level access… | |
| Aplazada | Media (5.3) | 0.31% | — | Stylemix MotorsAI | 14/8/2025 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Stylemix Motors motors-car-dealership-classified-listings allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Motors: from n/a through <= 1.4.80. | |
| Aplazada | Crítica (9) | 0.68% | — | Stylemixthemes Motors - EventsAI | 6/6/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in StylemixThemes Motors - Events stm-motors-events allows PHP Local File Inclusion.This issue affects Motors - Events: from n/a through <= 1.4.7. | |
| Aplazada | Crítica (9.8) | 16% | — | MotorsAI | 20/5/2025 | 17/6/2026 | The Motors theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 5.6.67. This is due to the theme not properly validating a user's identity prior to updating their password. This makes it possible for unauthenticated attackers to change arbitrary user… | |
| Aplazada | Alta (7.3) | 0.52% | — | THE MotorsAI | 3/5/2025 | 17/6/2026 | The The Motors - Car Dealer, Rental & Listing WordPress theme theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.6.65. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes… | |
| Aplazada | Alta (8.1) | 0.93% | — | Stylemix MotorsAI | 11/4/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Stylemix Motors motors-car-dealership-classified-listings allows PHP Local File Inclusion.This issue affects Motors: from n/a through <= 1.4.71. | |
| Analizada | Media (4.3) | 0.31% | — | Stylemixthemes Motors - CAR Dealer, Classifieds & Listing | 8/4/2025 | 17/6/2026 | The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several functions in the ajax_actions.php file in all versions up to, and including, 1.4.66. This makes it possible for authenticated attackers, with… |