---
id: CVE-2026-16750
title: >-
  The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress
  is vulnerable to unauthorized access of data due to missing authorization
  checks in mvl_ajax_dealer_load_cars() function in all versions up to, and
  including, …
summary: >-
  The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress
  is vulnerable to unauthorized access of data due to missing authorization
  checks in mvl_ajax_dealer_load_cars() function in all versions up to, and
  including, …
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-862
vendor: stylemix
product: Motors – Car Dealership & Classified Listings Plugin
affected:
  - motors_car_dealership_classified_listings_plugin <= 1.4.120
published: '2026-09-17'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T14:17:15.713'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-16750'
references:
  - url: 'https://plugins.trac.wordpress.org/changeset/3684170/'
    label: security@wordfence.com
  - url: >-
      https://www.wordfence.com/threat-intel/vulnerabilities/id/38d01b12-97ac-412b-b9df-c27118ce8f50?source=cve
    label: security@wordfence.com
tags:
  - nvd
  - cve.org
epss: 0.00244
epssPercentile: 0.13936
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-18T13:17:14.128478Z'
ingestedAt: '2026-09-17T22:30:21.396Z'
---

## Overview

The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to unauthorized access of data due to missing authorization checks in mvl_ajax_dealer_load_cars() function in all versions up to, and including, 1.4.120. This makes it possible for unauthenticated attackers to retrieve draft, pending, private, and future car listings belonging to arbitrary users.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
