Sceawere
Vulnerability Detail
CVE-2026-91022UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Motors Plugin Stored XSS
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.8
- Creation Date
- 17h ago
- Vendor
- Unknown
- Product
- Motors
- Attack Type
- CWE-79 Cross-Site Scripting (XSS)
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
The Motors WordPress plugin before 1.4.124 does not sanitise and escape a listing badge setting before outputting it inside an HTML attribute, allowing users with a custom, administrator-assigned listing-management role to inject arbitrary web scripts that execute when a listing is viewed by any visitor, including an administrator.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.8",
"pubDate": "2026-10-02T06:16:42.603Z",
"pubdate": "2026-10-02T06:16:42.603Z",
"executiveSummary": "The Motors WordPress plugin, in versions prior to 1.4.124, contains a stored Cross-Site Scripting (XSS) vulnerability within its listing badge management functionality.\nThis vulnerability stems from a failure to perform adequate input sanitization and output escaping on user-supplied data intended for use within HTML attributes.\nThe flaw allows an authenticated user, specifically one assigned a custom listing-management role, to inject arbitrary JavaScript payloads.\nThese payloads are subsequently rendered and executed in the browser of any user viewing the listing, including administrative accounts.\nThe impact is significant, as successful exploitation can lead to session hijacking, unauthorized actions performed on behalf of an administrator, or the redirection of visitors to malicious external sites.\nWhile the attack requires a specific, authenticated role, the persistent nature of stored XSS makes this a high-risk security flaw for any WordPress site utilizing the affected Motors plugin version.",
"technicalDetails": "The vulnerability is classified as a Stored Cross-Site Scripting (XSS) flaw, arising from improper handling of user-controllable input within the Motors plugin's listing management feature. Specifically, the plugin fails to sanitize or properly encode the data submitted for the 'listing badge' setting before it is echoed back into an HTML attribute during the rendering process.\nThe attack surface is limited to users granted a custom listing-management role, which is typically assigned via administrative privileges. Despite this authentication requirement, the vulnerability poses a severe risk due to the nature of stored XSS, which persists on the server and is triggered by the victim's interaction with the compromised listing.\nThe exploitation flow begins when an authenticated attacker, operating within the scope of the listing-management role, inputs a malicious JavaScript payload into the listing badge configuration field. Because the application logic does not employ context-aware output escaping (such as esc_attr() in WordPress), the payload is stored directly in the database.\nWhen a user—be it an administrator, a staff member, or a regular visitor—loads the page containing the affected listing, the plugin retrieves the unsanitized badge data and injects it directly into an HTML attribute (e.g., an 'alt', 'title', or 'class' attribute). The browser interprets the injected payload as part of the document structure, thereby executing the script within the security context of the victim's session.\nBecause the execution happens in the victim's browser session, a successful exploit can achieve full control over the victim's interactions with the WordPress site. If the victim is an administrator, the attacker can execute arbitrary administrative actions, such as creating new rogue user accounts, modifying plugin settings, or installing malicious themes/plugins. This effectively leads to full site compromise.\nThe vulnerability is present in all versions of the Motors plugin prior to 1.4.124. The fundamental issue is the lack of strict input validation at the point of ingestion and the failure to apply secure output encoding, which are mandatory security practices in WordPress plugin development."
}