Sceawere

Vulnerability Detail

CVE-2026-6806UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Motors Plugin Blind SQL Injection

Vulnerability Metadata

Severity
High
Score / CVSS
7.5
Creation Date
2h ago
Vendor
stylemix
Product
Motors – Car Dealership & Classified Listings Plugin
Attack Type
CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'stm_lat/stm_lng' parameter in all versions up to, and including, 1.4.109 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.5",
  "pubDate": "2026-09-30T08:16:34.090Z",
  "pubdate": "2026-09-30T08:16:34.090Z",
  "executiveSummary": "The Motors – Car Dealership & Classified Listings Plugin for WordPress is susceptible to a time-based blind SQL Injection vulnerability affecting all versions up to and including 1.4.109.\nThe flaw originates from improper input sanitization and a lack of parameterized queries when handling user-supplied data through the 'stm_lat' and 'stm_lng' parameters.\nThis vulnerability allows unauthenticated remote attackers to execute arbitrary SQL commands against the underlying WordPress database.\nBy leveraging time-based inference techniques—where the application's response latency is measured based on conditionally injected sleep commands—an attacker can reconstruct database content bit-by-bit.\nSuccessful exploitation poses a critical risk to data confidentiality, potentially exposing sensitive information such as user credentials, configuration settings, and proprietary business data.\nNo authentication is required to initiate the attack, making this a high-severity entry point for unauthenticated actors to perform unauthorized database enumeration.",
  "technicalDetails": "The vulnerability resides in the processing logic of the Motors plugin where the parameters 'stm_lat' and 'stm_lng' are received and incorporated into SQL queries without adequate escaping or the use of prepared statements.\nThis creates an injection vector where an attacker can supply crafted input designed to break out of the intended query context. Because the application does not utilize parameterized queries or abstraction layers that enforce strict typing, the database engine executes the injected malicious syntax as part of the primary query structure.\nThe exploitation method relies on time-based blind SQL injection. Since the application may not reflect the direct output of the injected SQL statement in the HTTP response body, the attacker utilizes database-native delay functions, such as 'SLEEP()' in MySQL, to infer information.\nThe attack flow follows a structured iterative process: First, the attacker sends a request containing a malicious payload injected into the 'stm_lat' or 'stm_lng' parameter. This payload typically includes a conditional statement: if a specific query result (e.g., the first character of the database admin password hash) matches a certain value, the database is instructed to pause for a defined duration before returning the response.\nBy observing the time delta between the request submission and the receipt of the server response, the attacker can determine whether the injected condition was true or false. Through thousands of such requests, the attacker automates the extraction of arbitrary data from the database, including the contents of tables containing sensitive PII or administrative authentication tokens.\nBecause this vulnerability is present at the application layer and accessible via standard web requests, the impact extends to full database exposure. An unauthenticated attacker can effectively bypass the standard application logic to dump sensitive tables, modify database entries, or extract internal configuration data that facilitates further post-exploitation activities.\nThe vulnerability is exposed directly via the web server to the public internet. Given that no session or privilege escalation is required, this allows for automated scanning and large-scale harvesting of site data by malicious actors."
}
CVE-2026-6806: Motors Plugin Blind SQL Injection (HIGH Severity, CVSS: 7.5) | Sceawere