CVE-2026-6806: Unauthenticated SQL Injection in The Motors WordPress Plugin
The Motors - Car Dealership & Classified Listings WordPress plugin is vulnerable to unauthenticated time-based blind SQL injection in versions up to 1.4.109, allowing remote attackers to extract sensitive database information.
CVE search metadata
CVE search record: CVE-2026-6806. Severity: high. CVSS: 7.5. KEV: no. Product: The Motors – Car Dealership & Classified Listings Plugin (<= 1.4.109). Brief: CVE-2026-6806: Unauthenticated SQL Injection in The Motors WordPress Plugin. Brief link: https://feed.craftedsignal.io/briefs/2026-09-motors-plugin-sqli/
The Motors - Car Dealership & Classified Listings plugin for WordPress contains a critical SQL injection vulnerability identified as CVE-2026-6806. The flaw exists in all versions up to and including 1.4.109. It stems from improper input sanitization and a lack of parameterized queries when processing the 'stm_lat' and 'stm_lng' parameters. An unauthenticated remote attacker can exploit this vulnerability by injecting malicious SQL payloads into these parameters, triggering time-based blind SQL injection. By observing the server response time variations, attackers can infer database content, potentially leading to unauthorized data extraction, including sensitive user information or administrative credentials stored within the WordPress database. Given that the plugin is used for classified listings, the impact to site confidentiality is significant.
Impact
Successful exploitation allows unauthenticated attackers to read arbitrary data from the WordPress database. This can lead to the compromise of user accounts, configuration settings, and private business data managed by the plugin. Organizations running affected versions are at high risk of data exfiltration.
Recommendation
- Update the 'The Motors - Car Dealership & Classified Listings Plugin' to the latest version available beyond 1.4.109 to include the necessary input escaping and query preparation.
- Monitor web application firewall (WAF) logs for abnormal HTTP POST or GET requests targeting plugin endpoints that contain SQL metacharacters (e.g., SLEEP, WAITFOR, BENCHMARK) within the 'stm_lat' or 'stm_lng' parameters.
- Restrict public access to non-essential administrative or listing-submission endpoints where possible until patching is completed.
Immediate actions
Upgrade The Motors plugin to the latest version post-1.4.109
Mitigations
Deploy WAF rules to filter SQL keywords in plugin parameters
CVE-2026-6806
Detection coverage 1
Detects CVE-2026-6806 Exploitation - SQL Injection in The Motors Plugin
highDetects attempts to exploit time-based blind SQL injection via stm_lat or stm_lng parameters in The Motors WordPress plugin
Detection queries are available on the platform. Get full rules →