CVE-2026-91022
Received Received - Intake

Stored Cross-Site Scripting in Motors WordPress Plugin

Vulnerability report for CVE-2026-91022, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: WPScan

Description

The Motors WordPress plugin before 1.4.124 does not sanitise and escape a listing badge setting before outputting it inside an HTML attribute, allowing users with a custom, administrator-assigned listing-management role to inject arbitrary web scripts that execute when a listing is viewed by any visitor, including an administrator.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
motors motors to 1.4.124 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a stored Cross-Site Scripting (XSS) vulnerability in the Motors WordPress plugin affecting versions before 1.4.124. It occurs because the plugin does not properly sanitize or escape user input in the listing badge setting. This allows users with a custom administrator-assigned listing-management role to inject malicious scripts into web pages.

Detection Guidance

Check if the Motors WordPress plugin version is below 1.4.124. Log in as an administrator and inspect the Listing Manager+ settings for the badge color field. Look for unexpected scripts or unusual HTML attributes in the output.

Impact Analysis

The injected scripts can execute when any visitor views the affected listing, including administrators. This could lead to unauthorized actions, data theft, or defacement of the website. Attackers might steal session cookies, redirect users to malicious sites, or perform actions on behalf of the user.

Compliance Impact

This vulnerability could lead to data breaches, exposing sensitive user data. For GDPR, it may result in unauthorized access to personal data, triggering reporting requirements and potential fines. For HIPAA, it could compromise protected health information, violating compliance standards.

Mitigation Strategies
  • Update the Motors plugin to version 1.4.124 or later immediately.
  • Review user roles with listing-management permissions and restrict unnecessary access.
  • Scan your WordPress site for any injected scripts in the badge settings or listings.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-91022. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart