Sceawere
Vulnerability Detail
CVE-2026-6806UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Motors Plugin Blind SQL Injection
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.5
- Creation Date
- 2h ago
- Vendor
- stylemix
- Product
- Motors – Car Dealership & Classified Listings Plugin
- Attack Type
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'stm_lat/stm_lng' parameter in all versions up to, and including, 1.4.109 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.5",
"pubDate": "2026-09-30T08:16:34.090Z",
"pubdate": "2026-09-30T08:16:34.090Z",
"executiveSummary": "The Motors – Car Dealership & Classified Listings Plugin for WordPress is susceptible to a time-based blind SQL Injection vulnerability affecting all versions up to and including 1.4.109.\nThe flaw originates from improper input sanitization and a lack of parameterized queries when handling user-supplied data through the 'stm_lat' and 'stm_lng' parameters.\nThis vulnerability allows unauthenticated remote attackers to execute arbitrary SQL commands against the underlying WordPress database.\nBy leveraging time-based inference techniques—where the application's response latency is measured based on conditionally injected sleep commands—an attacker can reconstruct database content bit-by-bit.\nSuccessful exploitation poses a critical risk to data confidentiality, potentially exposing sensitive information such as user credentials, configuration settings, and proprietary business data.\nNo authentication is required to initiate the attack, making this a high-severity entry point for unauthenticated actors to perform unauthorized database enumeration.",
"technicalDetails": "The vulnerability resides in the processing logic of the Motors plugin where the parameters 'stm_lat' and 'stm_lng' are received and incorporated into SQL queries without adequate escaping or the use of prepared statements.\nThis creates an injection vector where an attacker can supply crafted input designed to break out of the intended query context. Because the application does not utilize parameterized queries or abstraction layers that enforce strict typing, the database engine executes the injected malicious syntax as part of the primary query structure.\nThe exploitation method relies on time-based blind SQL injection. Since the application may not reflect the direct output of the injected SQL statement in the HTTP response body, the attacker utilizes database-native delay functions, such as 'SLEEP()' in MySQL, to infer information.\nThe attack flow follows a structured iterative process: First, the attacker sends a request containing a malicious payload injected into the 'stm_lat' or 'stm_lng' parameter. This payload typically includes a conditional statement: if a specific query result (e.g., the first character of the database admin password hash) matches a certain value, the database is instructed to pause for a defined duration before returning the response.\nBy observing the time delta between the request submission and the receipt of the server response, the attacker can determine whether the injected condition was true or false. Through thousands of such requests, the attacker automates the extraction of arbitrary data from the database, including the contents of tables containing sensitive PII or administrative authentication tokens.\nBecause this vulnerability is present at the application layer and accessible via standard web requests, the impact extends to full database exposure. An unauthenticated attacker can effectively bypass the standard application logic to dump sensitive tables, modify database entries, or extract internal configuration data that facilitates further post-exploitation activities.\nThe vulnerability is exposed directly via the web server to the public internet. Given that no session or privilege escalation is required, this allows for automated scanning and large-scale harvesting of site data by malicious actors."
}