CVE-2026-16750
MEDIUM
NVD
CVSS Score
5.3
Severity
MEDIUM
Published
Sep 17, 2026
Vendor
unknown
Description
The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to unauthorized access of data due to missing authorization checks in mvl_ajax_dealer_load_cars() function in all versions up to, and including, 1.4.120. This makes it possible for unauthenticated attackers to retrieve draft, pending, private, and future car listings belonging to arbitrary users.