The Motors WordPress plugin before 1.4.4 does not properly validate uploaded files for dangerous file types (such as .php) in an AJAX action, allowing an attacker to sign up on a victim's WordPress instance, upload a malicious PHP file and attempt to launch a brute-force attack to discover the uploaded payload.
History

Tue, 22 Apr 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2022-12-12T17:54:58.545Z

Updated: 2025-04-22T14:45:06.597Z

Reserved: 2022-11-14T14:45:02.983Z

Link: CVE-2022-3989

cve-icon Vulnrichment

Updated: 2024-08-03T01:27:54.119Z

cve-icon NVD

Status : Modified

Published: 2022-12-12T18:15:12.553

Modified: 2025-04-22T15:16:02.310

Link: CVE-2022-3989

cve-icon Redhat

No data.