Broken Access Control in Motors Theme by StylemixThemes
CVE-2026-93950

7.5HIGH

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
10 October 2026

What is CVE-2026-93950?

A security issue identified in the Motors theme developed by StylemixThemes involves a missing authorization flaw, which allows attackers to exploit incorrectly configured access control security levels. This vulnerability affects all versions of the Motors theme up to 1.4.108, potentially exposing sensitive functionalities and user data to unauthorized access.

Affected Version(s)

Motors 0 <= 1.4.108

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Baikuya | Patchstack Bug Bounty Program
.