Impact
The Motors WordPress plugin before version 1.4.124 allows authenticated users with subscriber‑level access or higher to modify listing metadata on posts they do not own, including the ability to overwrite product prices. This occurs because the plugin does not properly verify that the user is authorized to perform the listing‑management action, leading to a direct impact on data integrity and potential financial loss for owners of affected listings. The vulnerability is a missing authorization flaw (CWE‑862).
Affected Systems
The vulnerability affects the Motors plugin for WordPress, specifically all releases prior to 1.4.124. An affected system must also have WooCommerce installed and the paid featured‑listing option enabled, which are not part of WordPress or WooCommerce default configurations.
Risk and Exploitability
Exploitability requires an authenticated subscriber or higher account, WooCommerce active, and the paid featured listing feature enabled. The CVSS score of 3.1 indicates low severity, and the EPSS score of <1% indicates very low exploitation probability. The vulnerability is not listed in CISA KEV, implying limited publicly known exploitation. The likely attack vector is a crafted HTTP request directed at the stm_make_featured endpoint of the plugin. Though the overall risk is low, the potential impact on listing data and product pricing is significant if an attacker can satisfy the prerequisites.
OpenCVE Enrichment