PatchSiren cyber security CVE debrief
CVE-2026-91016 Motors CVE debrief
The Motors WordPress plugin before 1.4.121 does not verify that a request is authorized to view a user's non-published listings before returning them, allowing unauthenticated attackers to read any author's draft, pending and private car listings - including titles, prices, media URLs and seller notes - by supplying only the target's numeric user id.
- Vendor
- Motors
- Product
- Motors WordPress plugin
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-17
- Original CVE updated
- 2026-09-18
- Advisory published
- 2026-09-17
- Advisory updated
- 2026-09-18
Who should care
Defenders responsible for WordPress installations with the Motors plugin should assess exposure and prioritize verification and remediation, focusing on updating to version 1.4.121 or later and restricting access to sensitive listing information. This includes reviewing compensating controls for exposed systems, monitoring for unauthorized access attempts, and tracking exceptions and retesting remediated assets.
Why it matters
CVE-2026-91016 allows unauthenticated attackers to read non-published car listings in Motors WordPress plugin, requiring defenders to verify exposure and prioritize remediation.
- Unauthenticated access to sensitive listing information
- Potential data exposure for draft, pending, and private listings
- Need for verification of plugin version and exposure
- Prioritization of remediation for affected installations
Technical summary
The Motors WordPress plugin before version 1.4.121 does not verify authorization for requests to view non-published listings, allowing unauthenticated attackers to access draft, pending, and private car listings, including titles, prices, media URLs, and seller notes, by supplying only the target's numeric user id. This vulnerability requires defenders to assess exposure and prioritize verification and remediation, focusing on updating to version 1.4.121 or later and restricting access to sensitive listing information.
Defensive priority
Defenders should prioritize verifying exposure of Motors plugin versions before 1.4.121 and restrict access to sensitive listing information.
Recommended defensive actions
- Verify Motors plugin version and update to 1.4.121 or later
- Restrict access to sensitive listing information
- Monitor for unauthorized access attempts
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record and NVD entry provide details on the vulnerability in the Motors WordPress plugin before version 1.4.121. The vulnerability allows unauthenticated attackers to read non-published car listings by supplying only the target's numeric user id. Defenders should verify exposure and prioritize remediation, focusing on updating to version 1.4.121 or later and restricting access to sensitive listing information. Evidence from vendor sources and affected scope require verification, with a focus on draft, pending, and private car
Sources and references
Verified primary and authoritative sources
-
CVE-2026-91016 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-91016
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-91016 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-91016
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://wpscan.com/vulnerability/790e62ae-297b-4fcd-9650-b3b99a417713/
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.