logo

WordPress Motors theme flaw mass-exploited to hijack admin accounts

ID: c0140503-edca-5c28-a9f7-b7424c1cba11

STIX ID: report--c0140503-edca-5c28-a9f7-b7424c1cba11

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2025-06-21

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

**Executive Summary:** A critical privilege-escalation flaw (CVE-2025-4322) in the Motors WordPress theme enabled unauthenticated attackers to reset administrator passwords and take over sites; Wordfence observed active exploitation beginning May 20, 2025, with wide-scale attacks (Wordfence blocked 23,100 attempts) and published example payloads, attacker-set passwords, and IP addresses — site owners should apply the vendor patch (Motors 5.6.68), look for newly created admin accounts, and block malicious IPs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.