Impact
The vulnerability allows an unauthenticated attacker to store malicious scripts in comment content or user biographical information within the Motors plugin. When affected pages are viewed, the stored payload is rendered and executed by the victim’s browser, leading to theft of credentials, session hijacking, or defacement. This weakness is a classic example of Context‑Sensitive Injection (CWE‑79).
Affected Systems
WordPress sites running the Motors – Car Dealership & Classified Listings plugin version 1.4.112 or any earlier release are affected.
Risk and Exploitability
The CVSS score of 7.2 indicates a high potential impact, while the EPSS score of less than 1% suggests a low likelihood of exploitation at this time. The flaw is not listed in the CISA KEV catalog. Attackers can exploit it without authentication by submitting crafted content through the comment or user profile forms; they then rely on victims visiting the affected page where the script executes.
OpenCVE Enrichment