Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-16750— Motors – Car Dealership & Classified Listings <= 1.4.120 - Missing Authorization to Unauthenticated Private/Draft/Password-Protected Listings Exposure

Quick assessment

Affected
stylemix Motors – Car Dealership & Classified Listings Plugin
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

WordPress 插件“The Motors – Car Dealership & Classified Listings”在 1.4.120 及之前版本中,由于 函数中缺少授权检查,导致存在未授权数据访问漏洞。这使得未经身份验证的攻击者能够获取任意用户的草稿、待发布、私有以及未来日期的汽车列表数据。

CVSS 5.3 · Medium

Possible ATT&CK Techniques 1 AI

T1566 · Phishing
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-16750

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Motors – Car Dealership & Classified Listings <= 1.4.120 - Missing Authorization to Unauthenticated Private/Draft/Password-Protected Listings Exposure
Source: CVE Program / CVE List V5
Vulnerability Description
The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to unauthorized access of data due to missing authorization checks in mvl_ajax_dealer_load_cars() function in all versions up to, and including, 1.4.120. This makes it possible for unauthenticated attackers to retrieve draft, pending, private, and future car listings belonging to arbitrary users.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制缺失
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
stylemix Motors – Car Dealership & Classified Listings Plugin 0 ~ 1.4.120 -

II. Public POCs for CVE-2026-16750

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-16750

登录查看更多情报信息。

Patches & Fixes for CVE-2026-16750 (1)

Vendor Pages for CVE-2026-16750 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-16750

No comments yet


Leave a comment