CVE-2026-91023: CWE-862 Missing Authorization in Motors
The Motors WordPress plugin before 1.4.124 does not properly verify that a user is authorised to modify a listing before processing one of its listing management actions, allowing authenticated attackers with subscriber-level access and above to set metadata on posts they do not own, including overwriting product prices. Exploitation is possible only when WooCommerce is active and the Motors WordPress plugin before 1.4.124's paid featured-listing option is enabled, neither of which is a default configuration.
AI Analysis
Technical Summary
CVE-2026-91023 is a missing authorization vulnerability (CWE-862) in the Motors WordPress plugin versions prior to 1.4.124. The plugin fails to properly verify user authorization before processing listing management actions, enabling authenticated users with subscriber-level access or above to set metadata on posts they do not own. This can lead to unauthorized modification of listing details, including product prices. Exploitation is conditional on WooCommerce being active and the paid featured-listing option enabled in the plugin.
Potential Impact
Authenticated attackers with subscriber-level access or higher can modify metadata on listings they do not own, including overwriting product prices. This could lead to unauthorized changes in product pricing and listing details. However, exploitation requires specific conditions: WooCommerce must be active and the paid featured-listing option enabled, neither of which are default configurations.
Mitigation Recommendations
A fix is available in Motors WordPress plugin version 1.4.124. Users should upgrade to version 1.4.124 or later to remediate this vulnerability. Until patched, restricting subscriber-level access and disabling the paid featured-listing option or WooCommerce integration can reduce exposure.
CVE-2026-91023: CWE-862 Missing Authorization in Motors
Description
The Motors WordPress plugin before 1.4.124 does not properly verify that a user is authorised to modify a listing before processing one of its listing management actions, allowing authenticated attackers with subscriber-level access and above to set metadata on posts they do not own, including overwriting product prices. Exploitation is possible only when WooCommerce is active and the Motors WordPress plugin before 1.4.124's paid featured-listing option is enabled, neither of which is a default configuration.
CVSS v3.1
Score 3.1low
Affected software
Motors
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-91023 is a missing authorization vulnerability (CWE-862) in the Motors WordPress plugin versions prior to 1.4.124. The plugin fails to properly verify user authorization before processing listing management actions, enabling authenticated users with subscriber-level access or above to set metadata on posts they do not own. This can lead to unauthorized modification of listing details, including product prices. Exploitation is conditional on WooCommerce being active and the paid featured-listing option enabled in the plugin.
Potential Impact
Authenticated attackers with subscriber-level access or higher can modify metadata on listings they do not own, including overwriting product prices. This could lead to unauthorized changes in product pricing and listing details. However, exploitation requires specific conditions: WooCommerce must be active and the paid featured-listing option enabled, neither of which are default configurations.
Mitigation Recommendations
A fix is available in Motors WordPress plugin version 1.4.124. Users should upgrade to version 1.4.124 or later to remediate this vulnerability. Until patched, restricting subscriber-level access and disabling the paid featured-listing option or WooCommerce integration can reduce exposure.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- WPScan
- Date Reserved
- 2026-09-14T17:07:28.393Z
- State
- PUBLISHED
Threat ID: 6abf4919a43b0b3b897a0ebd
Added to database: 10/02/2026, 06:03:05 UTC
Last enriched: 10/02/2026, 06:16:20 UTC
Last updated: 10/03/2026, 03:12:15 UTC
Views: 22
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.