Motors WordPress Vulnerability Exposes Sites to Takeover
ID: 2086008b-688f-519c-91b2-354caa7e453c
STIX ID: report--2086008b-688f-519c-91b2-354caa7e453c
Feed Name: Infosecurity Magazine (News)
Threat Score
A critical arbitrary file upload vulnerability (CVE-2025-64374) in the Motors WordPress theme (<= 5.6.81) allowed logged-in users with Subscriber-level privileges to upload and activate plugins via an AJAX handler that relied on a nonce but lacked a proper current_user_can() permission check. The flaw could lead to full site takeover on affected sites (over 20,000 installations); the issue was patched in Motors 5.6.82 and administrators are strongly advised to update.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
