Impact
The vulnerable code in the Motors WordPress plugin, when running any version older than 1.4.124, never sanitises or escapes the badge colour value supplied by a user with a listing‑management role. The unchecked value is inserted unmodified into an HTML attribute, permitting an attacker to embed arbitrary JavaScript that runs automatically whenever a visitor, including an administrator, opens a listing page.
Affected Systems
The vulnerability affects the Motors WordPress plugin for all installations that have not been updated to version 1.4.124 or higher. All users of older plugin releases are potentially exposed.
Risk and Exploitability
No CVSS score is provided and the EPSS for this flaw is not available, so a precise numeric risk assessment cannot be offered. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires the attacker to possess the custom, administrator‑assigned listing‑management role. Once the privileged role is in place, the stored XSS is triggered automatically for anyone who views a listing.
OpenCVE Enrichment