CVE-2026-91022 PUBLISHED

Motors < 1.4.124 - Listing Manager+ Stored XSS via Badge Color

Assigner: WPScan
Reserved: 14.09.2026 Published: 02.10.2026 Updated: 02.10.2026

The Motors WordPress plugin before 1.4.124 does not sanitise and escape a listing badge setting before outputting it inside an HTML attribute, allowing users with a custom, administrator-assigned listing-management role to inject arbitrary web scripts that execute when a listing is viewed by any visitor, including an administrator.

Product Status

Vendor Unknown
Product Motors
Versions Default: unaffected
  • affected from 0 to 1.4.124 (excl.)

Credits

  • Yaswanth Reddy Sunkara finder
  • WPScan coordinator

References

Problem Types

  • CWE-79 Cross-Site Scripting (XSS) CWE