Impact
This vulnerability is an improper neutralization of input during web page generation that allows a stored cross‑site scripting (XSS) attack. By inserting malicious script payloads into data stored by the Motors plugin, an attacker can execute arbitrary JavaScript in the context of any victim who views the injected content. The resulting impact includes session hijacking, defacement, or data theft. The weakness is a classic input validation failure (CWE‑79).
Affected Systems
The security issue affects the Stylemix Motors Motors‑Car‑Dealership‑Classified‑Listings WordPress plugin in all releases up to and including version 1.4.71. Any WordPress site that has installed this version of the plugin is vulnerable.
Risk and Exploitability
The CVSS base score is 6.5, indicating a moderate severity. The EPSS score is listed as less than 1%, meaning the likelihood of exploitation is very low at the time of this analysis, and the vulnerability is not currently in the CISA KEV catalog. The most probable attack vector involves an attacker submitting malicious input via the plugin’s forms, which is then stored and displayed to other users. This requires that the site has the vulnerable plugin installed and that the injected content is displayed to visitors. No authentication is required for the stored XSS to be executed once the payload is stored.
OpenCVE Enrichment
EUVD