← back
CVE-2026-91023lowCWE-862

Motors – Car Dealership & Classified Listings < 1.4.124 - Subscriber+ Cross-User Post Meta Modification via stm_make_featured

28Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendcvss 3.1epss 0.1%
exploitation probability
0.1%top 98% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
The Motors WordPress plugin before 1.4.124 does not properly verify that a user is authorised to modify a listing before processing one of its listing management actions, allowing authenticated attackers with subscriber-level access and above to set metadata on posts they do not own, including overwriting product prices. Exploitation is possible only when WooCommerce is active and the Motors WordPress plugin before 1.4.124's paid featured-listing option is enabled, neither of which is a default configuration.
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
Affected products
Unknown · Motors
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.