CVE-2026-91016 - Motors < 1.4.121 - Unauthenticated Draft/Private Listing Disclosure
CVE ID :CVE-2026-91016
Published : Sept. 17, 2026, 6:16 a.m. | 51 minutes ago
Description :The Motors WordPress plugin before 1.4.121 does not verify that a request is authorized to view a user's non-published listings before returning them, allowing unauthenticated attackers to read any author's draft, pending and private car listings - including titles, prices, media URLs and seller notes - by supplying only the target's numeric user id.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Sept. 17, 2026, 6:16 a.m. | 51 minutes ago
Description :The Motors WordPress plugin before 1.4.121 does not verify that a request is authorized to view a user's non-published listings before returning them, allowing unauthenticated attackers to read any author's draft, pending and private car listings - including titles, prices, media URLs and seller notes - by supplying only the target's numeric user id.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...