CVE-2026-91016: Unknown Motors
Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.
The Motors WordPress plugin before 1.4.121 does not verify that a request is authorized to view a user's non-published listings before returning them, allowing unauthenticated attackers to read any author's draft, pending and private car listings - including titles, prices, media URLs and seller notes - by supplying only the target's numeric user id.
Affected products
- Unknown Motors: before 1.4.121 (fixed in 1.4.121)
Published 2026-09-17. Last modified 2026-09-18.