MEDIUM (5.0)
    Plugin

    Payment Bypass Vulnerability in Motors – Car Dealership & Classified Listings Plugin

    Published Date: 5/12/2026
    CVE ID: CVE-2026-1934

    Summary

    The Motors plugin for WordPress up to version 1.4.103 is vulnerable to a payment bypass due to insecure handling of user meta updates. Unauthorized users with Subscriber-level access can manipulate user meta fields to gain premium features without completing payment transactions.

    Vulnerability Details

    The vulnerability lies in the way the stm_save_user_extra_fields() function handles sensitive user meta fields in the Motors plugin. This function, triggered by the 'personal_options_update' action, allows update operations based solely on the current_user_can('edit_user', $user_id) check, which does not properly restrict users from altering their own payment status meta field. Consequently, authenticated users can update their payment status to 'completed', bypassing any actual payment verification process. This exploit enables unauthorized access to features reserved for paid Dealer membership levels, undermining the secure transaction integrity intended by the plugin. Without proper verification and authorization checks, potentially malicious users can exploit this loophole, resulting in financial losses for site owners.

    Recommendations

    Immediate steps should include reviewing and tightening user permissions related to meta field updates, particularly for users with Subscriber-level access. Verify that only appropriately authorized roles can modify sensitive payment-related fields. Consider implementing additional nonce checks and capability checks to ensure that only legitimate payment actions can alter payment statuses. Regular audits of user permissions and access logs can help detect any unauthorized access patterns.

    Available Fixes

    Last Updated: 5/13/2026
    Jedar

    Jedar for Digital Rights is a non-profit organization dedicated to protecting digital freedoms, enhancing online privacy, and promoting secure digital practices for vulnerable communities worldwide.

    Follow Us

    All Rights Reserved © 2026 Jedar for Digital Rights.

    Cookie Preferences

    We use cookies to enhance your browsing experience, serve personalized ads or content, and analyze our traffic. By clicking "Accept All", you consent to our use of cookies.

    Learn More