๐Ÿ” CVE Alert

CVE-2026-91022

UNKNOWN 0.0

Motors < 1.4.124 - Listing Manager+ Stored XSS via Badge Color

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Motors WordPress plugin before 1.4.124 does not sanitise and escape a listing badge setting before outputting it inside an HTML attribute, allowing users with a custom, administrator-assigned listing-management role to inject arbitrary web scripts that execute when a listing is viewed by any visitor, including an administrator.

Vendor unknown
Product motors
Published Oct 2, 2026
Stay Ahead of the Next One

Get instant alerts for unknown motors

Be the first to know when new unknown vulnerabilities affecting unknown motors are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Motors
0 < 1.4.124

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/72672806-e2f3-417e-83c0-854c604028e4/

Credits

Yaswanth Reddy Sunkara WPScan