Sceawere

Vulnerability Detail

CVE-2026-96563UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Motors Plugin Stored XSS

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.4
Creation Date
2h ago
Vendor
stylemix
Product
Motors – Car Dealership & Classified Listings Plugin
Attack Type
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'stm_f_s' parameter in all versions up to, and including, 1.4.123 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The nonce required by the stm_ajax_add_a_car AJAX handler is emitted in wp_footer on every page, making it accessible to any authenticated user and removing any practical barrier to exploitation at the Subscriber level.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.4",
  "pubDate": "2026-10-10T08:17:07.703Z",
  "pubdate": "2026-10-10T08:17:07.703Z",
  "executiveSummary": "The Motors – Car Dealership & Classified Listings Plugin for WordPress is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability. This flaw exists in versions up to and including 1.4.123. The vulnerability stems from improper input sanitization and output escaping within the 'stm_f_s' parameter. An authenticated attacker possessing subscriber-level privileges or higher can inject malicious JavaScript payloads that execute in the context of other users' sessions. The impact is significant, as it allows for unauthorized script execution, session hijacking, or unauthorized administrative actions. Exploitation is facilitated by the insecure exposure of the required AJAX nonce in the 'wp_footer' of every page, effectively removing the intended CSRF protection. Consequently, any authenticated user can successfully bypass security controls to trigger the vulnerable 'stm_ajax_add_a_car' AJAX handler, leading to persistent payload storage. This vulnerability poses a severe risk to site integrity and user data confidentiality, necessitating immediate remediation efforts by administrators.",
  "technicalDetails": "The vulnerability is located within the 'stm_ajax_add_a_car' AJAX handler provided by the Motors plugin. The root cause is the lack of rigorous input validation and sanitization on the 'stm_f_s' parameter before it is processed and stored in the database. Because the application fails to escape the content upon retrieval and rendering, any malicious JavaScript injected into this parameter is executed by the browser of any user who views the page containing the injected content.\nThe exploitation flow begins with the attacker obtaining the required security nonce. In this WordPress implementation, the nonce necessary for the 'stm_ajax_add_a_car' action is rendered directly into the HTML source of every page via the 'wp_footer' hook. This architectural design flaw makes the nonce available to any authenticated user, including those with minimal privileges such as Subscribers. Once the attacker retrieves the valid nonce, they can craft a POST request targeting the 'wp_ajax_stm_ajax_add_a_car' endpoint.\nThe attacker sends an HTTP request containing the legitimate nonce and a crafted payload within the 'stm_f_s' parameter. Since the application does not properly sanitize this input, the payload is persisted into the WordPress database. When a target user, such as an administrator or another site visitor, navigates to a page where the injected data is rendered, the application outputs the raw malicious script directly into the Document Object Model (DOM).\nThe payload executes in the context of the victim's session, allowing the attacker to perform actions on behalf of the victim, steal session cookies, capture sensitive information, or perform unauthorized site modifications. Since the script executes whenever the page is loaded, the XSS is persistent, creating a long-term threat until the malicious entry is removed from the database by an administrator. The requirement of authentication is trivialized by the wide availability of the nonce, effectively lowering the barrier for exploitation to any authenticated account on the platform."
}
CVE-2026-96563: Motors Plugin Stored XSS (MEDIUM Severity, CVSS: 6.4) | Sceawere