Impact
Motors WordPress plugin versions before 1.4.121 lack an authorization check for unpublished listings. An attacker who knows a user’s numeric ID can request that value and receive full details of any draft, pending, or private car listings, including titles, prices, media URLs and seller notes, thereby leaking sensitive information and potentially compromising user privacy.
Affected Systems
The vulnerability affects the Motors plugin for WordPress on any installation of version 1.4.120 and older. No other vendors or products are impacted. Users of the affected plugin should verify the installed version and consider updating if it is below 1.4.121.
Risk and Exploitability
The CVSS base score of 5.3 indicates a moderate impact with no denial‑of‑service or code execution potential. The EPSS score of less than 1 % suggests a low likelihood of exploitation at present, and the vulnerability is not listed in the CISA KEV catalog. Attack requires only external access and knowledge of a user ID; it does not require elevated privileges. If an attacker discovers a target ID, the compromise is straightforward and passive, resulting in a discrete breach of confidential listing data.
OpenCVE Enrichment