CVE-2026-91016
Motors < 1.4.121 - Unauthenticated Draft/Private Listing Disclosure
CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th
The Motors WordPress plugin before 1.4.121 does not verify that a request is authorized to view a user's non-published listings before returning them, allowing unauthenticated attackers to read any author's draft, pending and private car listings - including titles, prices, media URLs and seller notes - by supplying only the target's numeric user id.
| Vendor | unknown |
| Product | motors |
| Published | Sep 17, 2026 |
| Last Updated | Sep 17, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown motors
Be the first to know when new medium vulnerabilities affecting unknown motors are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Motors
0 < 1.4.121
References
Credits
Pedro Pinho WPScan