WordPress Plugin Vulnerabilities

Motors – Car Dealership & Classified Listings < 1.4.124 - Subscriber+ Cross-User Post Meta Modification via stm_make_featured

Description

The plugin does not properly verify that a user is authorised to modify a listing before processing one of its listing management actions, allowing authenticated attackers with subscriber-level access and above to set metadata on posts they do not own, including overwriting product prices. Exploitation is possible only when WooCommerce is active and the plugin's paid featured-listing option is enabled, neither of which is a default configuration.

Proof of Concept

Affects Plugins

References

Classification

Type
NO AUTHORISATION
CWE
CVSS

Miscellaneous

Original Researcher
Yaswanth Reddy Sunkara
Submitter
Yaswanth Reddy Sunkara
Verified
Yes

Timeline

Publicly Published
2026-09-30 (about 2 days ago)
Added
2026-09-30 (about 1 day ago)
Last Updated
2026-09-30 (about 1 day ago)

Other