CVE-2026-54814: WordPress Motors plugin <= 1.4.109 - Local File Inclusion vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in StylemixThemes Motors allows PHP Local File Inclusion.
This issue affects Motors: from n/a through 1.4.109.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wordpress/motorsto a version that resolves this vulnerability.Fixed in 1.4.110
Event History
Frequently Asked Questions
What is the severity of CVE-2026-54814?
CVE-2026-54814 has a severity rating of high with a score of 8.1.
How do I fix CVE-2026-54814?
To fix CVE-2026-54814, update the StylemixThemes Motors plugin to a version later than 1.4.109.
What type of vulnerability is CVE-2026-54814?
CVE-2026-54814 is a Local File Inclusion vulnerability.
Which versions of the Motors plugin are affected by CVE-2026-54814?
CVE-2026-54814 affects the StylemixThemes Motors plugin from any version up to and including 1.4.109.
What impact does CVE-2026-54814 have on security?
CVE-2026-54814 can lead to unauthorized access to sensitive files on the server due to improper control of file inclusion.