CVE-2026-1934 MEDIUM

CVE-2026-1934: Motors – Car Dealership & Classified Listings Plugin <= 1.4.103 - Missing Authorization to Authenticated (Subscriber+) Payment Bypass via 'stm_payment_status' Parameter

Vendor Stylemix
Product Motors – Car Dealership & Classified Listings Plugin
Weakness CWE-862 · Missing authorization
Published May 12, 2026
Last update May 12, 2026

CVSS base score

4.3/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality None
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

What the vulnerability does

01Description

The Motors – Car Dealership & Classified Listings plugin for WordPress is vulnerable to Payment Bypass via insecure user meta update in all versions up to, and including, 1.4.103 This is due to the stm_save_user_extra_fields() function updating sensitive user meta fields from POST data without verifying that the current user should have permission to modify those fields. The function hooks into the 'personal_options_update' action and only checks current_user_can('edit_user', $user_id), which passes for any user editing their own profile. This makes it possible for authenticated attackers, with Subscriber-level access and above, to set their stm_payment_status to 'completed', bypassing the PayPal payment verification and gaining access to paid Dealer membership features without completing any transaction.

Explanation of Vulnerability in Simple Terms

02Summary

The Motors car dealership plugin for WordPress does not properly check user permissions before allowing certain actions. A logged-in user with low privileges can modify data they should not have access to. The vulnerability affects all versions up to 1.4.103. Update to a version newer than 1.4.103 when available.

What an attacker can do

03Attacker Capabilities

A low-privilege logged-in user can modify data they should not have access to.

Potential impact on your site

04Site Impact

Unauthorized users can alter listings, settings, or other plugin data depending on what permissions are missing.

Conditions required to exploit

05Prerequisites

Attacker must have a low-privilege account on the WordPress site.

Key dates

06Disclosure timeline

May 12, 2026 CVE published
May 12, 2026 Record updated