Description
The Motors WordPress plugin before 1.4.124 does not properly verify that a user is authorised to modify a listing before processing one of its listing management actions, allowing authenticated attackers with subscriber-level access and above to set metadata on posts they do not own, including overwriting product prices. Exploitation is possible only when WooCommerce is active and the Motors WordPress plugin before 1.4.124's paid featured-listing option is enabled, neither of which is a default configuration.
Published: 2026-10-02
Score: 3.1 Low
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized data modification
Action: Immediate Patch
AI Analysis

Impact

The Motors WordPress plugin before version 1.4.124 allows authenticated users with subscriber‑level access or higher to modify listing metadata on posts they do not own, including the ability to overwrite product prices. This occurs because the plugin does not properly verify that the user is authorized to perform the listing‑management action, leading to a direct impact on data integrity and potential financial loss for owners of affected listings. The vulnerability is a missing authorization flaw (CWE‑862).

Affected Systems

The vulnerability affects the Motors plugin for WordPress, specifically all releases prior to 1.4.124. An affected system must also have WooCommerce installed and the paid featured‑listing option enabled, which are not part of WordPress or WooCommerce default configurations.

Risk and Exploitability

Exploitability requires an authenticated subscriber or higher account, WooCommerce active, and the paid featured listing feature enabled. The CVSS score of 3.1 indicates low severity, and the EPSS score of <1% indicates very low exploitation probability. The vulnerability is not listed in CISA KEV, implying limited publicly known exploitation. The likely attack vector is a crafted HTTP request directed at the stm_make_featured endpoint of the plugin. Though the overall risk is low, the potential impact on listing data and product pricing is significant if an attacker can satisfy the prerequisites.

Generated by OpenCVE AI on October 2, 2026 at 14:27 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Motors plugin to version 1.4.124 or later.
  • Disable the paid featured‑listing option in the plugin settings to remove the vulnerable functionality.
  • If possible, remove WooCommerce or isolate the Motors plugin to reduce the attack surface.

Generated by OpenCVE AI on October 2, 2026 at 14:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress-extensions
Wordpress-extensions motors
Vendors & Products Wordpress-extensions
Wordpress-extensions motors

Fri, 02 Oct 2026 11:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-862
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 02 Oct 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Motors WordPress plugin before 1.4.124 does not properly verify that a user is authorised to modify a listing before processing one of its listing management actions, allowing authenticated attackers with subscriber-level access and above to set metadata on posts they do not own, including overwriting product prices. Exploitation is possible only when WooCommerce is active and the Motors WordPress plugin before 1.4.124's paid featured-listing option is enabled, neither of which is a default configuration.
Title Motors – Car Dealership & Classified Listings < 1.4.124 - Subscriber+ Cross-User Post Meta Modification via stm_make_featured
References

Subscriptions

Wordpress-extensions Motors
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-10-02T10:54:11.568Z

Reserved: 2026-09-14T17:07:28.393Z

Link: CVE-2026-91023

cve-icon Vulnrichment

Updated: 2026-10-02T10:44:15.352Z

cve-icon NVD

Status : Deferred

Published: 2026-10-02T06:16:42.740

Modified: 2026-10-02T18:00:34.733

Link: CVE-2026-91023

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T14:46:31Z

Weaknesses