Impact
The plugin’s stm_f_s parameter is not sanitized, letting authenticated subscribers inject scripts that are stored and executed when the page loads. This results in the ability to run arbitrary JavaScript in users’ browsers, compromising confidentiality, integrity, and potentially defacing content.
Affected Systems
WordPress sites using the stylemix Motors – Car Dealership & Classified Listings Plugin version 1.4.123 or earlier are affected. No specific OS or PHP version restrictions are noted. The issue exists in all versions up to and including 1.4.123.
Risk and Exploitability
The CVSS score of 6.4 indicates moderate severity. The absence of an EPSS score means current exploitation probability is unknown, but the vulnerability is not listed in the CISA KEV catalog. The attack requires only subscriber‑level authentication, and the nonce is publicly available via the footer, making exploitation straightforward for any authenticated user. Reducing the risk relies on updating the plugin or applying an equivalent mitigation.
OpenCVE Enrichment