<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>The Motors – Car Dealership &amp; Classified Listings Plugin (&lt;= 1.4.109) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/the-motors--car-dealership--classified-listings-plugin--1.4.109/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 30 Sep 2026 08:33:17 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/the-motors--car-dealership--classified-listings-plugin--1.4.109/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>CVE-2026-6806: Unauthenticated SQL Injection in The Motors WordPress Plugin</title><link>https://feed.craftedsignal.io/briefs/2026-09-motors-plugin-sqli/</link><pubDate>Wed, 30 Sep 2026 08:33:17 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-motors-plugin-sqli/</guid><description>The Motors - Car Dealership &amp; Classified Listings WordPress plugin is vulnerable to unauthenticated time-based blind SQL injection in versions up to 1.4.109, allowing remote attackers to extract sensitive database information.</description><content:encoded><![CDATA[<p>The Motors - Car Dealership &amp; Classified Listings plugin for WordPress contains a critical SQL injection vulnerability identified as CVE-2026-6806. The flaw exists in all versions up to and including 1.4.109. It stems from improper input sanitization and a lack of parameterized queries when processing the 'stm_lat' and 'stm_lng' parameters. An unauthenticated remote attacker can exploit this vulnerability by injecting malicious SQL payloads into these parameters, triggering time-based blind SQL injection. By observing the server response time variations, attackers can infer database content, potentially leading to unauthorized data extraction, including sensitive user information or administrative credentials stored within the WordPress database. Given that the plugin is used for classified listings, the impact to site confidentiality is significant.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows unauthenticated attackers to read arbitrary data from the WordPress database. This can lead to the compromise of user accounts, configuration settings, and private business data managed by the plugin. Organizations running affected versions are at high risk of data exfiltration.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Update the 'The Motors - Car Dealership &amp; Classified Listings Plugin' to the latest version available beyond 1.4.109 to include the necessary input escaping and query preparation.</li>
<li>Monitor web application firewall (WAF) logs for abnormal HTTP POST or GET requests targeting plugin endpoints that contain SQL metacharacters (e.g., SLEEP, WAITFOR, BENCHMARK) within the 'stm_lat' or 'stm_lng' parameters.</li>
<li>Restrict public access to non-essential administrative or listing-submission endpoints where possible until patching is completed.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>web-application</category><category>sql-injection</category><category>wordpress</category><category>cve-2026-6806</category></item></channel></rss>