CVE Watchtower

← Back to CVE List

CVE-2026-16750Wordfence

Description

The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to unauthorized access of data due to missing authorization checks in mvl_ajax_dealer_load_cars() function in all versions up to, and including, 1.4.120. This makes it possible for unauthenticated attackers to retrieve draft, pending, private, and future car listings belonging to arbitrary users.
Severity Level
MEDIUM (5.3)
Published Date
17/09/2026
Last Modified
17/09/2026
Exploitation Status
????
EPSS Score
0.24% (percentile 15.9%)

CVSS Base Metrics

CVSS v3 (3.x)
MEDIUM 5.3
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Weaknesses (CWE)

CWE-862 - Missing Authorization

Affected & Patched Versions

ProductAffected VersionsPatched Version
Motors – Car Dealership & Classified Listings PluginN/A1.4.121
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.