CVE-2026-91023 PUBLISHED

Motors – Car Dealership & Classified Listings < 1.4.124 - Subscriber+ Cross-User Post Meta Modification via stm_make_featured

Assigner: WPScan
Reserved: 14.09.2026 Published: 02.10.2026 Updated: 02.10.2026

The Motors WordPress plugin before 1.4.124 does not properly verify that a user is authorised to modify a listing before processing one of its listing management actions, allowing authenticated attackers with subscriber-level access and above to set metadata on posts they do not own, including overwriting product prices. Exploitation is possible only when WooCommerce is active and the Motors WordPress plugin before 1.4.124's paid featured-listing option is enabled, neither of which is a default configuration.

Product Status

Vendor Unknown
Product Motors
Versions Default: unaffected
  • affected from 0 to 1.4.124 (excl.)

Credits

  • Yaswanth Reddy Sunkara finder
  • WPScan coordinator

References

Problem Types

  • CWE-862 Missing Authorization CWE