Loading market data...
← Back to CVE feed

CVE-2026-91022

MEDIUM CVSS 6.8 View on NVD ↗

Description

The Motors WordPress plugin before 1.4.124 does not sanitise and escape a listing badge setting before outputting it inside an HTML attribute, allowing users with a custom, administrator-assigned listing-management role to inject arbitrary web scripts that execute when a listing is viewed by any visitor, including an administrator.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
Published: Oct 02, 2026 06:16 UTC Modified: Oct 02, 2026 18:00 UTC