PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-91016 Motors CVE debrief

The Motors WordPress plugin before 1.4.121 does not verify that a request is authorized to view a user's non-published listings before returning them, allowing unauthenticated attackers to read any author's draft, pending and private car listings - including titles, prices, media URLs and seller notes - by supplying only the target's numeric user id.

Vendor
Motors
Product
Motors WordPress plugin
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-17
Original CVE updated
2026-09-18
Advisory published
2026-09-17
Advisory updated
2026-09-18

Who should care

Defenders responsible for WordPress installations with the Motors plugin should assess exposure and prioritize verification and remediation, focusing on updating to version 1.4.121 or later and restricting access to sensitive listing information. This includes reviewing compensating controls for exposed systems, monitoring for unauthorized access attempts, and tracking exceptions and retesting remediated assets.

Why it matters

CVE-2026-91016 allows unauthenticated attackers to read non-published car listings in Motors WordPress plugin, requiring defenders to verify exposure and prioritize remediation.

  • Unauthenticated access to sensitive listing information
  • Potential data exposure for draft, pending, and private listings
  • Need for verification of plugin version and exposure
  • Prioritization of remediation for affected installations

Technical summary

The Motors WordPress plugin before version 1.4.121 does not verify authorization for requests to view non-published listings, allowing unauthenticated attackers to access draft, pending, and private car listings, including titles, prices, media URLs, and seller notes, by supplying only the target's numeric user id. This vulnerability requires defenders to assess exposure and prioritize verification and remediation, focusing on updating to version 1.4.121 or later and restricting access to sensitive listing information.

Defensive priority

Defenders should prioritize verifying exposure of Motors plugin versions before 1.4.121 and restrict access to sensitive listing information.

Recommended defensive actions

  • Verify Motors plugin version and update to 1.4.121 or later
  • Restrict access to sensitive listing information
  • Monitor for unauthorized access attempts
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and NVD entry provide details on the vulnerability in the Motors WordPress plugin before version 1.4.121. The vulnerability allows unauthenticated attackers to read non-published car listings by supplying only the target's numeric user id. Defenders should verify exposure and prioritize remediation, focusing on updating to version 1.4.121 or later and restricting access to sensitive listing information. Evidence from vendor sources and affected scope require verification, with a focus on draft, pending, and private car

Sources and references

Verified primary and authoritative sources

  • CVE-2026-91016 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-91016

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-91016 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-91016

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.