Medium severity6.4NVD Advisory· Published Oct 10, 2026
CVE-2026-96563
CVE-2026-96563
Description
The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'stm_f_s' parameter in all versions up to, and including, 1.4.123 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The nonce required by the stm_ajax_add_a_car AJAX handler is emitted in wp_footer on every page, making it accessible to any authenticated user and removing any practical barrier to exploitation at the Subscriber level.
Affected products
1- Range: <=1.4.123
Patches
Vulnerability mechanics
References
7- plugins.trac.wordpress.org/browser/motors-car-dealership-classified-listings/tags/1.4.123/assets/js/frontend/filter.jsnvd
- plugins.trac.wordpress.org/browser/motors-car-dealership-classified-listings/tags/1.4.123/assets/js/frontend/filter.jsnvd
- plugins.trac.wordpress.org/browser/motors-car-dealership-classified-listings/tags/1.4.123/assets/js/frontend/init.jsnvd
- plugins.trac.wordpress.org/browser/motors-car-dealership-classified-listings/tags/1.4.123/assets/js/frontend/init.jsnvd
- plugins.trac.wordpress.org/browser/motors-car-dealership-classified-listings/tags/1.4.123/includes/vehicle_functions.phpnvd
- plugins.trac.wordpress.org/browser/motors-car-dealership-classified-listings/tags/1.4.123/includes/vehicle_functions.phpnvd
- www.wordfence.com/threat-intel/vulnerabilities/id/14bb850e-df8a-46f0-b320-d8aedd763901nvd
News mentions
0No linked articles in our index yet.