CVE-2026-1934: Motors – Car Dealership & Classified Listings Plugin <= 1.4.103 - Missing Authorization to Authenticated (Subscriber+) Payment Bypass via 'stm_payment_status' Parameter

Published May 12, 2026
·
Updated

The Motors – Car Dealership & Classified Listings plugin for WordPress is vulnerable to Payment Bypass via insecure user meta update in all versions up to, and including, 1.4.103 This is due to the stmsaveuserextrafields() function updating sensitive user meta fields from POST data without verifying that the current user should have permission to modify those fields. The function hooks into the 'personaloptionsupdate' action and only checks currentusercan('edituser', $userid), which passes for any user editing their own profile. This makes it possible for authenticated attackers, with Subscriber-level access and above, to set their stmpaymentstatus to 'completed', bypassing the PayPal payment verification and gaining access to paid Dealer membership features without completing any transaction.

Affected Software

1 affected component
StylemixThemes Motors – Car Dealership & Classified Listings<=1.4.103

Event History

May 12, 2026
CVE Published
via MITRE·08:27 AM
Data Sourced
via MITRE·08:27 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:16 AM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-1934?

CVE-2026-1934 has been assessed as having a high severity due to the potential for unauthorized payment bypass.

2

How do I fix CVE-2026-1934?

To fix CVE-2026-1934, update the Motors – Car Dealership & Classified Listings plugin to the latest version beyond 1.4.103.

3

Who is affected by CVE-2026-1934?

CVE-2026-1934 affects users of the Motors – Car Dealership & Classified Listings plugin for WordPress versions 1.4.103 and earlier.

4

What types of exploits can occur with CVE-2026-1934?

Exploiting CVE-2026-1934 allows unauthorized users to bypass payment authorization, potentially leading to financial loss.

5

Is CVE-2026-1934 being actively exploited?

There have been reports of CVE-2026-1934 being actively exploited, making it critical to apply the necessary updates.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203