Executive brief
The Motors WordPress plugin, used for car dealership and classified listing websites, contains a security flaw that allows unauthorized users to modify website content. An attacker can remotely change image galleries, featured images, and even product prices on sites using WooCommerce. This could lead to financial loss through price manipulation or reputational damage via unauthorized website defacement.
Technical details
The vulnerability exists in the 'stm_ajax_add_a_car_media' AJAX action due to a lack of authorization and CSRF validation. An unauthenticated attacker can send a crafted POST request to wp-admin/admin-ajax.php to modify metadata for any post where the 'stm_car_user' meta is unset. This includes blog posts, pages, and WooCommerce products. Impacted metadata includes '_thumbnail_id', gallery arrays, and, if WooCommerce and pay-per-listing are configured, the '_price' field. The issue is fixed in version 1.4.110.
Affected products
- StylemixThemes Motors Car Dealership & Classified Listings < 1.4.110
Timeline
- 2026-06-01: disclosed: Publicly published by WPScan
- 2026-06-22: advisory: NVD published the CVE record