LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →

CVE-2026-3892 - Vulnerability Analysis

HighCVSS: 8.1

Last Updated: May 14, 2026

The Motors – Car Dealership & Classified Listings Plugin - Arbitrary File Deletion

Published: May 14, 2026Updated: May 14, 2026Remote Exploitable

Overview

The Motors – Car Dealership & Classified Listings Plugin for WordPress <= 1.4.107 contains an arbitrary file deletion vulnerability caused by insufficient file path validation in the become-dealer logo upload flow, letting authenticated attackers with subscriber access delete arbitrary files on the server.

Severity & Score

Severity: High
CVSS Score: 8.1
EPSS Score: 4.7%(Probability of exploitation in next 30 days)

Impact

Authenticated attackers can delete arbitrary files on the server, potentially disrupting service or deleting critical data.

Mitigation

Update to the latest version beyond 1.4.107.

Social Media Activity(2 posts)

TheHackerWire
TheHackerWire
@thehackerwire
May 14, 2026

🟠 CVE-2026-3892 - High (8.1) The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including, 1.4.107. This is due to insufficient file path validation in the become-dealer logo uplo... 🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-3892/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post
TheHackerWire
TheHackerWire
@thehackerwire
May 14, 2026

🟠 CVE-2026-3892 - High (8.1) The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including, 1.4.107. This is due to insufficient file path validation in the become-dealer logo uplo... 🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-3892/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post

Details

CVE ID
CVE-2026-3892
Severity
High
CVSS Score
8.1
Type
undefined
Status
rejected
EPSS
4.7%
Social Posts
2

CWE

  • CWE-73

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

EPSS Score

4.7%Probability of exploitation in the next 30 days