Sceawere

Vulnerability Detail

CVE-2026-91023UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Motors Plugin Unauthorized Metadata Manipulation

Vulnerability Metadata

Severity
Low
Score / CVSS
3.1
Creation Date
17h ago
Vendor
Unknown
Product
Motors
Attack Type
CWE-862 Missing Authorization
Vector String
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
Attack Complexity
HIGH

Narrative and Response

Description

The Motors WordPress plugin before 1.4.124 does not properly verify that a user is authorised to modify a listing before processing one of its listing management actions, allowing authenticated attackers with subscriber-level access and above to set metadata on posts they do not own, including overwriting product prices. Exploitation is possible only when WooCommerce is active and the Motors WordPress plugin before 1.4.124's paid featured-listing option is enabled, neither of which is a default configuration.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "3.1",
  "pubDate": "2026-10-02T06:16:42.740Z",
  "pubdate": "2026-10-02T06:16:42.740Z",
  "executiveSummary": "The Motors WordPress plugin, in versions prior to 1.4.124, contains an Insecure Direct Object Reference (IDOR) vulnerability that facilitates unauthorized metadata modification.\nThe vulnerability allows authenticated users with subscriber-level privileges or higher to manipulate listing metadata for posts they do not own, effectively bypassing access control mechanisms.\nThe primary security impact involves the ability to overwrite critical post attributes, including product pricing data associated with WooCommerce integrations.\nSuccessful exploitation requires that WooCommerce is active and the plugin's paid featured-listing option is enabled, neither of which represent default plugin configurations.\nThis flaw poses significant risks to e-commerce integrity, potentially allowing attackers to modify product values, disrupt business operations, or engage in fraudulent pricing activities.\nThe root cause is a failure to implement server-side authorization checks during the processing of listing management actions.",
  "technicalDetails": "The vulnerability stems from an authorization bypass flaw located within the Motors plugin's listing management functionality. The plugin fails to validate the current user's permissions or ownership of the specific listing ID passed during the request lifecycle.\nWhen a user triggers a listing management action, the plugin processes the request and updates associated post metadata without ensuring the requester is the authorized owner or holds sufficient administrative privileges. Because the application logic relies on user-supplied parameters to identify the target listing, an attacker can modify the metadata of any arbitrary post within the system, provided the post supports the metadata structure used by the plugin.\nExploitation is contingent upon the concurrent activation of the WooCommerce plugin and the enabling of the paid featured-listing functionality within the Motors settings. These specific conditions initialize the code paths vulnerable to the flawed authorization logic.\nThe attack flow begins when an authenticated subscriber identifies an HTTP request responsible for updating post metadata, such as a feature-toggle or pricing update request. By intercepting the request and modifying the 'post_id' or similar identifier parameter, the attacker can redirect the plugin's internal database update functions to target unauthorized posts. Upon submission, the plugin performs the database update operation without re-validating the user's authority to modify the target record.\nIn environments where WooCommerce is active, this allows the attacker to inject or overwrite product metadata, including the '_price' attribute. The integrity of the WooCommerce pricing mechanism is therefore undermined, as the attacker can manipulate the value returned by the database during the checkout or display process.\nThis vulnerability is effectively an IDOR vulnerability, as it allows users to perform unauthorized actions on objects by manipulating object identifiers. The impact is persistent, as the metadata changes are written directly to the WordPress database, potentially affecting site-wide pricing structures or display settings until manually reverted by an administrator."
}
CVE-2026-91023: Motors Plugin Unauthorized Metadata Manipulation (LOW Severity, CVSS: 3.1) | Sceawere