CVE-2026-91023
Received Received - Intake

Privilege Escalation in Motors WordPress Plugin

Vulnerability report for CVE-2026-91023, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: WPScan

Description

The Motors WordPress plugin before 1.4.124 does not properly verify that a user is authorised to modify a listing before processing one of its listing management actions, allowing authenticated attackers with subscriber-level access and above to set metadata on posts they do not own, including overwriting product prices. Exploitation is possible only when WooCommerce is active and the Motors WordPress plugin before 1.4.124's paid featured-listing option is enabled, neither of which is a default configuration.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
motors motors to 1.4.124 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the WordPress plugin 'Motors – Car Dealership & Classified Listings' versions before 1.4.124. It allows authenticated users with subscriber-level access or higher to modify post metadata, including overwriting product prices, on listings they do not own due to improper authorization checks before processing listing management actions.

Detection Guidance

Check the installed version of the Motors WordPress plugin. If it is below 1.4.124, the system is vulnerable. Use WordPress admin panel or run: wp plugin list | grep motors. Exploitation may involve unauthorized metadata changes, so review post metadata for unexpected modifications.

Impact Analysis

An attacker could change product prices on listings they do not own, potentially leading to financial losses or fraud. This requires WooCommerce to be active and the plugin's paid featured-listing option enabled, which are not default settings.

Mitigation Strategies

Update the Motors WordPress plugin to version 1.4.124 or later immediately. Disable the paid featured-listing option if not required. Ensure WooCommerce is updated to the latest secure version. Monitor post metadata for unauthorized changes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-91023. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart