{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3astylemixthemesthe_motorswordpress/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:stylemixthemes:the_motors:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-6806"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["The Motors – Car Dealership \u0026 Classified Listings Plugin (\u003c= 1.4.109)"],"_cs_severities":["high"],"_cs_tags":["web-application","sql-injection","wordpress","cve-2026-6806"],"_cs_type":"advisory","_cs_vendors":["WordPress"],"content_html":"\u003cp\u003eThe Motors - Car Dealership \u0026amp; Classified Listings plugin for WordPress contains a critical SQL injection vulnerability identified as CVE-2026-6806. The flaw exists in all versions up to and including 1.4.109. It stems from improper input sanitization and a lack of parameterized queries when processing the 'stm_lat' and 'stm_lng' parameters. An unauthenticated remote attacker can exploit this vulnerability by injecting malicious SQL payloads into these parameters, triggering time-based blind SQL injection. By observing the server response time variations, attackers can infer database content, potentially leading to unauthorized data extraction, including sensitive user information or administrative credentials stored within the WordPress database. Given that the plugin is used for classified listings, the impact to site confidentiality is significant.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to read arbitrary data from the WordPress database. This can lead to the compromise of user accounts, configuration settings, and private business data managed by the plugin. Organizations running affected versions are at high risk of data exfiltration.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the 'The Motors - Car Dealership \u0026amp; Classified Listings Plugin' to the latest version available beyond 1.4.109 to include the necessary input escaping and query preparation.\u003c/li\u003e\n\u003cli\u003eMonitor web application firewall (WAF) logs for abnormal HTTP POST or GET requests targeting plugin endpoints that contain SQL metacharacters (e.g., SLEEP, WAITFOR, BENCHMARK) within the 'stm_lat' or 'stm_lng' parameters.\u003c/li\u003e\n\u003cli\u003eRestrict public access to non-essential administrative or listing-submission endpoints where possible until patching is completed.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-30T08:33:17Z","date_published":"2026-09-30T08:33:17Z","id":"https://feed.craftedsignal.io/briefs/2026-09-motors-plugin-sqli/","summary":"The Motors - Car Dealership \u0026 Classified Listings WordPress plugin is vulnerable to unauthenticated time-based blind SQL injection in versions up to 1.4.109, allowing remote attackers to extract sensitive database information.","title":"CVE-2026-6806: Unauthenticated SQL Injection in The Motors WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-09-motors-plugin-sqli/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:stylemixthemes:the_motors:*:*:*:*:*:wordpress:*:*","version":"https://jsonfeed.org/version/1.1"}