CVE-2026-6806 Overview
CVE-2026-6806 is a time-based blind SQL injection vulnerability in the Motors – Car Dealership & Classified Listings Plugin for WordPress. The flaw affects all plugin versions up to and including 1.4.109. Unauthenticated attackers can inject arbitrary SQL through the stm_lat and stm_lng request parameters. Successful exploitation lets attackers extract sensitive data from the WordPress database, including credentials and session tokens. The issue is tracked under CWE-89: SQL Injection and resolved in version 1.4.110.
Critical Impact
Unauthenticated attackers can extract database contents, including user credentials, from any WordPress site running an affected version of the Motors plugin.
Affected Products
- Motors – Car Dealership & Classified Listings Plugin for WordPress
- All versions up to and including 1.4.109
- Fixed in version 1.4.110
Discovery Timeline
- 2026-09-30 - CVE-2026-6806 published to NVD
- 2026-09-30 - Last updated in NVD database
Technical Details for CVE-2026-6806
Vulnerability Analysis
The Motors plugin exposes geolocation-aware search functionality that accepts stm_lat and stm_lng parameters from HTTP requests. These values are concatenated into a SQL statement without sufficient escaping or the use of prepared statements. Attackers control the raw input reaching the query, which enables SQL syntax injection.
Exploitation follows a time-based blind pattern. The attacker submits payloads containing conditional SLEEP() calls and infers query results from response latency. This technique is reliable even when the application returns no direct database output. Because the vulnerable endpoint requires no authentication, exploitation scales to any internet-reachable installation.
Root Cause
The root cause is improper neutralization of special elements in SQL commands, classified as CWE-89. The plugin fails to apply wpdb::prepare() or equivalent parameterization to user-supplied latitude and longitude values. Direct string concatenation of untrusted input into the SQL query allows the injected clauses to execute in the database context.
Attack Vector
The attack is delivered over the network without user interaction or credentials. An attacker crafts an HTTP request to a vulnerable endpoint that consumes the stm_lat or stm_lng parameter. The injected payload contains conditional time-delay functions that reveal database contents one boolean condition at a time. See the Wordfence advisory for endpoint details.
No verified public exploit code is available at publication. Refer to the WordPress plugin changeset for the corrective code.
Detection Methods for CVE-2026-6806
Indicators of Compromise
- HTTP requests containing stm_lat or stm_lng parameters with SQL keywords such as SLEEP, BENCHMARK, UNION, or SELECT.
- Unusually long response times from Motors plugin search endpoints, indicating time-based payload execution.
- Repeated requests from a single source iterating through parameter values with slight variations.
- Web server access logs showing URL-encoded SQL syntax (%27, %20OR%20, %20AND%20) in the affected parameters.
Detection Strategies
- Deploy web application firewall rules that inspect stm_lat and stm_lng values for SQL metacharacters and time-delay function names.
- Enable MySQL slow query logging and alert on queries exceeding baseline latency originating from the plugin.
- Correlate HTTP 200 responses with anomalous response duration to identify successful blind injection probes.
- Monitor WordPress database for unexpected SELECT activity against wp_users and wp_usermeta tables.
Monitoring Recommendations
- Ingest web server, WAF, and database logs into a centralized analytics platform and build detections keyed to the vulnerable parameters.
- Track outbound data volume from the WordPress host to identify bulk exfiltration following exploitation.
- Alert on any administrator account creation or password reset event that follows suspicious stm_lat or stm_lng traffic.
How to Mitigate CVE-2026-6806
Immediate Actions Required
- Update the Motors – Car Dealership & Classified Listings Plugin to version 1.4.110 or later without delay.
- Audit web server access logs for prior requests targeting stm_lat or stm_lng with SQL syntax and treat matches as potential compromise.
- Rotate all WordPress administrator credentials, API keys, and secrets stored in the database if exploitation is suspected.
- Review the wp_users table for unauthorized accounts and privilege changes.
Patch Information
The vendor addressed the vulnerability in version 1.4.110 by adding proper parameterization to the affected SQL query. The corrective code is available in the WordPress plugin changeset 3552483.
Workarounds
- Deactivate the Motors plugin until the update to 1.4.110 can be applied.
- Configure a WAF rule to block requests where stm_lat or stm_lng values contain non-numeric characters.
- Restrict access to the affected search endpoint via IP allowlisting where feasible.
# Example WAF rule concept - reject non-numeric geo parameters
# ModSecurity example
SecRule ARGS:stm_lat "!@rx ^-?[0-9]+(\.[0-9]+)?$" \
"id:1026806,phase:2,deny,status:403,msg:'Invalid stm_lat value - CVE-2026-6806'"
SecRule ARGS:stm_lng "!@rx ^-?[0-9]+(\.[0-9]+)?$" \
"id:1026807,phase:2,deny,status:403,msg:'Invalid stm_lng value - CVE-2026-6806'"
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
