Back

LOW

Motors – Car Dealership & Classified Listings < 1.4.124 - Subscriber+ Cross-User Post Meta Modification via stm_make_featured

Published Oct 2, 2026

Description

The Motors WordPress plugin before 1.4.124 does not properly verify that a user is authorised to modify a listing before processing one of its listing management actions, allowing authenticated attackers with subscriber-level access and above to set metadata on posts they do not own, including overwriting product prices. Exploitation is possible only when WooCommerce is active and the Motors WordPress plugin before 1.4.124's paid featured-listing option is enabled, neither of which is a default configuration.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner WPScan
Published Oct 2, 2026
Updated Oct 2, 2026
Reserved Sep 14, 2026
CISA Vulnrichment
Updated Oct 2, 2026
NVD
Status Deferred
Modified Oct 2, 2026
Red Hat
Severity n/a
Public date n/a