CVE-2025-32170: WordPress Motors plugin <= 1.4.71 - Cross Site Scripting (XSS) vulnerability
Published Apr 4, 2025
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Stylemix Motors motors-car-dealership-classified-listings allows Stored XSS.This issue affects Motors: from n/a through <= 1.4.71.
Affected Software
1 affected component
StylemixThemes Motors (WordPress plugin)<=1.4.71
Event History
Apr 4, 2025
CVE Published
via MITRE·03:58 PM
Data Sourced
via MITRE·03:58 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-32170?
CVE-2025-32170 has been rated with a medium severity due to its potential to allow stored XSS attacks.
2
How do I fix CVE-2025-32170?
To fix CVE-2025-32170, update the Stylemix Motors plugin to version 1.4.66 or later.
3
What are the main impacts of CVE-2025-32170?
The main impacts of CVE-2025-32170 include the risk of unauthorized script execution in user browsers leading to data theft or session hijacking.
4
Which versions are affected by CVE-2025-32170?
CVE-2025-32170 affects Stylemix Motors versions up to and including 1.4.65.
5
Is user input involved in the exploit of CVE-2025-32170?
Yes, CVE-2025-32170 exploits improper neutralization of user input during web page generation.