CVE-2025-69317
CarSpot
Minimum safe version
2.4.6
Update to 2.4.6 or later to address 11 fixable vulnerabilities
CVE-2024-12860
CarSpot < 2.2.3 - Multiple Vulnerabilities
CarSpot – Dealership Wordpress Classified Theme <= 2.2.3 - Insecure Direct Object Reference
CarSpot – Dealership Wordpress Classified Theme <= 2.2.3 - Stored Cross-Site Scripting
WordPress CarSpot theme <= 2.1.6 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability
WordPress CarSpot premium theme <= 2.2.2 - Insecure Direct Object References (IDOR) vulnerability
WordPress CarSpot premium theme <= 2.2.2 - Authenticated Persistent Cross-Site Scripting (XSS) vulnerability (ad post)
WordPress CarSpot premium theme <= 2.2.2 - Authenticated Persistent Cross-Site Scripting (XSS) vulnerability (registration form & user profile)
WordPress CarSpot theme <= 2.2.0 - Multiple Vulnerabilities (Authenticated Persistent XSS & IDOR)
CVE-2019-15870