CVE-2026-96563
Description
The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'stm_f_s' parameter in all versions up to, and including, 1.4.123 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The nonce required by the stm_ajax_add_a_car AJAX handler is emitted in wp_footer on every page, making it accessible to any authenticated user and removing any practical barrier to exploitation at the Subscriber level.
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or — if you've already worked around this in production — publish your fix to the community-verified tier.
Propose a mitigation on Community Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
References
- https://plugins.trac.wordpress.org/browser/motors-car-dealership-classified-listings/tags/1.4.123/assets/js/frontend/filter.js#L724
- https://plugins.trac.wordpress.org/browser/motors-car-dealership-classified-listings/tags/1.4.123/assets/js/frontend/filter.js#L751
- https://plugins.trac.wordpress.org/browser/motors-car-dealership-classified-listings/tags/1.4.123/assets/js/frontend/init.js#L311
- https://plugins.trac.wordpress.org/browser/motors-car-dealership-classified-listings/tags/1.4.123/assets/js/frontend/init.js#L337
- https://plugins.trac.wordpress.org/browser/motors-car-dealership-classified-listings/tags/1.4.123/includes/vehicle_functions.php#L1199
- https://plugins.trac.wordpress.org/browser/motors-car-dealership-classified-listings/tags/1.4.123/includes/vehicle_functions.php#L1432
- https://www.wordfence.com/threat-intel/vulnerabilities/id/14bb850e-df8a-46f0-b320-d8aedd763901?source=cve
CWEs
CWE-79
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.