Description
Insertion of Sensitive Information Into Sent Data vulnerability in StylemixThemes Motors allows Retrieve Embedded Sensitive Data.

This issue affects Motors: from n/a through 1.4.124.
Published: 2026-10-06
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: Sensitive Data Exposure
Action: Update Plugin
AI Analysis

Impact

The WordPress Motors plugin contains a Vulnerability that allows an attacker to retrieve sensitive information that should not be transmitted within the plugin’s output. This is an insertion of sensitive data into sent content, classified under CWE‑201, and has a CVSS score of 6.9 meaning it can lead to moderate confidentiality impact.

Affected Systems

The affected product is StylemixThemes’ WordPress Motors plugin for WordPress. All versions from any release prior to 1.4.125, including up to and including 1.4.124, are vulnerable.

Risk and Exploitability

The CVSS score of 6.9 indicates a moderate risk profile. The EPSS score is not available, so the probability of exploitation is unknown, and it is not listed in CISA’s KEV catalog. Based on the functionality of the plugin, the likely attack vector is remote via web requests to the site; the vulnerability is exploitable without local access, so any user who can interact with the plugin’s output could potentially retrieve the leaked data.

Generated by OpenCVE AI on October 6, 2026 at 10:35 UTC.

Remediation

Vendor Solution

Update the WordPress Motors plugin to the latest available version (at least 1.4.125).


OpenCVE Recommended Actions

  • Update the WordPress Motors plugin to version 1.4.125 or later as recommended by the vendor.
  • If the update cannot be applied immediately, disable the plugin or restrict access to its pages until the patch is applied.
  • Review the configuration of the plugin to ensure that only authorized users can access any sensitive data and enforce proper access controls.

Generated by OpenCVE AI on October 6, 2026 at 10:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 06 Oct 2026 09:00:00 +0000

Type Values Removed Values Added
Description Insertion of Sensitive Information Into Sent Data vulnerability in StylemixThemes Motors allows Retrieve Embedded Sensitive Data. This issue affects Motors: from n/a through 1.4.124.
Title WordPress Motors plugin <= 1.4.124 - Sensitive Data Exposure vulnerability
Weaknesses CWE-201
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-06T10:31:25.740Z

Reserved: 2026-10-02T00:22:13.105Z

Link: CVE-2026-104399

cve-icon Vulnrichment

Updated: 2026-10-06T10:27:53.673Z

cve-icon NVD

Status : Received

Published: 2026-10-06T09:17:38.860

Modified: 2026-10-06T11:17:14.667

Link: CVE-2026-104399

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T10:45:06Z

Weaknesses
  • CWE-201

    Insertion of Sensitive Information Into Sent Data