---
id: CVE-2026-91023
title: >-
  The Motors  WordPress plugin before 1.4.124 does not properly verify that a
  user is authorised to modify a listing before processing one of its listing
  management actions, allowing authenticated attackers with subscriber-level
  access and…
summary: >-
  The Motors  WordPress plugin before 1.4.124 does not properly verify that a
  user is authorised to modify a listing before processing one of its listing
  management actions, allowing authenticated attackers with subscriber-level
  access and…
severity: low
cvss: 3.1
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N'
cwe:
  - CWE-862
product: Motors
affected:
  - Motors < 1.4.124
published: '2026-10-02'
updated: '2026-10-02'
sourceUpdated: '2026-10-02T18:00:34.733'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-91023'
references:
  - url: 'https://wpscan.com/vulnerability/c2400c65-5d77-454c-9691-5e664556341b/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
epss: 0.00132
epssPercentile: 0.02327
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-10-02T10:45:34.165660Z'
ingestedAt: '2026-10-02T06:11:20.484Z'
---

## Overview

The Motors  WordPress plugin before 1.4.124 does not properly verify that a user is authorised to modify a listing before processing one of its listing management actions, allowing authenticated attackers with subscriber-level access and above to set metadata on posts they do not own, including overwriting product prices. Exploitation is possible only when WooCommerce is active and the Motors  WordPress plugin before 1.4.124's paid featured-listing option is enabled, neither of which is a default configuration.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
