High 7.1
2026-03-25< 1.6.8
CVE-2026-24391
Minimum safe version
1.6.8
Update to 1.6.8 or later to address 8 fixable vulnerabilities
CVE-2026-24391
CVE-2025-39480
Cardealer <= 1.6.4 - Cross-Site Request Forgery to User Update via update_user_profile
Cardealer <= 1.6.4 - Missing Authorization to Authenticated (Subscriber+) Change and Delete JS and CSS Files
Cardealer <= 1.6.4 - Arbitrary Theme Option Update to Authenticated (Subscriber+) Privilege Escalation
WordPress Car Dealer Theme <= 1.6.3 is vulnerable to Arbitrary File Deletion
CVE-2015-9483
wpscan.com
CVE-2015-9482