PT-2025-22122 · WordPress · Motors

Friderika Baranyai

·

Published

2025-05-20

·

Updated

2025-07-28

·

CVE-2025-4322

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Motors theme for WordPress versions up to, and including, 5.6.67
Description The Motors theme for WordPress is vulnerable to privilege escalation via account takeover. This is due to the theme not properly validating a user's identity prior to updating their password, making it possible for unauthenticated attackers to change arbitrary user passwords, including those of administrators, and leverage that to gain access to their account. It is estimated that over 22,000 sites are at risk.
Recommendations Update to version 5.6.68 to resolve the issue. As a temporary workaround, consider restricting access to password update functionality until a patch is available. Avoid using the password update feature in the affected theme until the issue is resolved.

Fix

LPE

Weakness Enumeration

Related Identifiers

CVE-2025-4322

Affected Products

Motors