CVE-2026-96563
MEDIUM
NVD
CVSS Score
6.4
Severity
MEDIUM
Published
Oct 10, 2026
Vendor
unknown
Description
The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'stm_f_s' parameter in all versions up to, and including, 1.4.123 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The nonce required by the stm_ajax_add_a_car AJAX handler is emitted in wp_footer on every page, making it accessible to any authenticated user and removing any practical barrier to exploitation at the Subscriber level.
References
- https://plugins.trac.wordpress.org/browser/motors-car-dealership-classified-listings/tags/1.4.123/assets/js/frontend/filter.js#L724
- https://plugins.trac.wordpress.org/browser/motors-car-dealership-classified-listings/tags/1.4.123/assets/js/frontend/filter.js#L751
- https://plugins.trac.wordpress.org/browser/motors-car-dealership-classified-listings/tags/1.4.123/assets/js/frontend/init.js#L311
- https://plugins.trac.wordpress.org/browser/motors-car-dealership-classified-listings/tags/1.4.123/assets/js/frontend/init.js#L337
- https://plugins.trac.wordpress.org/browser/motors-car-dealership-classified-listings/tags/1.4.123/includes/vehicle_functions.php#L1199