Skip to content
Threat Feed
high advisory

CVE-2026-6806: Unauthenticated SQL Injection in The Motors WordPress Plugin

The Motors - Car Dealership & Classified Listings WordPress plugin is vulnerable to unauthenticated time-based blind SQL injection in versions up to 1.4.109, allowing remote attackers to extract sensitive database information.

CVE search metadata

CVE search record: CVE-2026-6806. Severity: high. CVSS: 7.5. KEV: no. Product: The Motors – Car Dealership & Classified Listings Plugin (<= 1.4.109). Brief: CVE-2026-6806: Unauthenticated SQL Injection in The Motors WordPress Plugin. Brief link: https://feed.craftedsignal.io/briefs/2026-09-motors-plugin-sqli/

The Motors - Car Dealership & Classified Listings plugin for WordPress contains a critical SQL injection vulnerability identified as CVE-2026-6806. The flaw exists in all versions up to and including 1.4.109. It stems from improper input sanitization and a lack of parameterized queries when processing the 'stm_lat' and 'stm_lng' parameters. An unauthenticated remote attacker can exploit this vulnerability by injecting malicious SQL payloads into these parameters, triggering time-based blind SQL injection. By observing the server response time variations, attackers can infer database content, potentially leading to unauthorized data extraction, including sensitive user information or administrative credentials stored within the WordPress database. Given that the plugin is used for classified listings, the impact to site confidentiality is significant.

Impact

Successful exploitation allows unauthenticated attackers to read arbitrary data from the WordPress database. This can lead to the compromise of user accounts, configuration settings, and private business data managed by the plugin. Organizations running affected versions are at high risk of data exfiltration.

Recommendation

  • Update the 'The Motors - Car Dealership & Classified Listings Plugin' to the latest version available beyond 1.4.109 to include the necessary input escaping and query preparation.
  • Monitor web application firewall (WAF) logs for abnormal HTTP POST or GET requests targeting plugin endpoints that contain SQL metacharacters (e.g., SLEEP, WAITFOR, BENCHMARK) within the 'stm_lat' or 'stm_lng' parameters.
  • Restrict public access to non-essential administrative or listing-submission endpoints where possible until patching is completed.

Immediate actions

Upgrade The Motors plugin to the latest version post-1.4.109

IT Operations 24h

Mitigations

Deploy WAF rules to filter SQL keywords in plugin parameters

immediate SOC

CVE-2026-6806

Detection coverage 1

Detects CVE-2026-6806 Exploitation - SQL Injection in The Motors Plugin

high

Detects attempts to exploit time-based blind SQL injection via stm_lat or stm_lng parameters in The Motors WordPress plugin

sigma tactics: initial_access techniques: T1190 sources: webserver

Detection queries are available on the platform. Get full rules →