First published: Mon Feb 24 2020(Updated: )
includes/options.php in the motors-car-dealership-classified-listings (aka Motors - Car Dealer & Classified Ads) plugin through 1.4.0 for WordPress has multiple stored XSS issues.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Stylemixthemes Motors - Car Dealer\, Classifieds \& Listing | <=1.4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-17229 is a stored XSS vulnerability in the motors-car-dealership-classified-listings plugin for WordPress.
The severity of CVE-2019-17229 is medium with a CVSS score of 6.1.
CVE-2019-17229 allows attackers to perform stored XSS attacks through the includes/options.php file in the motors-car-dealership-classified-listings plugin.
To fix CVE-2019-17229, update the motors-car-dealership-classified-listings plugin to version 1.4.1 or later.
You can find more information about CVE-2019-17229 [here](https://blog.nintechnet.com/multiple-vulnerabilities-in-wordpress-motors-car-dealer-classified-ads-plugin/), [here](https://wordpress.org/plugins/motors-car-dealership-classified-listings/#developers), and [here](https://wpvulndb.com/vulnerabilities/9884).