CVE-2026-91016: Unknown Motors

Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.

The Motors WordPress plugin before 1.4.121 does not verify that a request is authorized to view a user's non-published listings before returning them, allowing unauthenticated attackers to read any author's draft, pending and private car listings - including titles, prices, media URLs and seller notes - by supplying only the target's numeric user id.

Affected products

  • Unknown Motors: before 1.4.121 (fixed in 1.4.121)

Published 2026-09-17. Last modified 2026-09-18.