Skip to content
  • Blog Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form

Motors Theme Vulnerability Exploited to Hack WordPress Websites

Posted on June 20, 2025June 20, 2025 By CWS

Mass exploitation of a critical-severity vulnerability within the Motors theme for WordPress began a number of weeks after public disclosure, WordPress safety agency Defiant warns.

The Motors theme is geared toward automotive dealership companies, together with automobile, motorbike, boat, and automobile rental sellers, providing pre-built web sites and templates, and help for itemizing, person and supplier administration.

The exploited vulnerability, tracked as CVE-2025-4322 (CVSS rating of 9.8), is described as a privilege escalation concern by way of account takeover.

The bug exists as a result of the theme fails to correctly validate person identities previous to updating account passwords, which permits attackers to vary the password of any person account.

“This makes it doable for unauthenticated attackers to vary arbitrary person passwords, together with these of directors, and leverage that to realize entry to their account,” a NIST advisory reads.

The safety defect was patched on Could 14 and publicly disclosed on Could 19. In accordance with Defiant, the primary exploitation makes an attempt focusing on the bug had been noticed on Could 20, whereas mass exploitation began on June 7.

The WordPress safety agency warns that over 22,000 web sites are utilizing the theme, and that it has blocked greater than 23,000 exploit makes an attempt focusing on CVE-2025-4322 because the vulnerability was publicly disclosed.

The difficulty impacts the theme’s Login Register widget, which incorporates the susceptible password restoration perform. As a result of the perform doesn’t forestall password updates if the hash from the person meta worth is empty, an attacker can replace the person’s password if the person has not requested a password reset.Commercial. Scroll to proceed studying.

Profitable exploitation of the safety defect, Defiant notes, can result in full web site compromise, as it might present attackers with entry to all administrative capabilities.

“This contains the power to add plugin and theme recordsdata, which will be malicious zip recordsdata containing backdoors, and to switch posts and pages which will be leveraged to redirect web site customers to different malicious websites or inject spam content material,” the safety agency explains.

CVE-2025-4322 was resolved in Motors theme model 5.6.68. Customers are suggested to replace to the patched model or a more recent launch as quickly as doable.

Associated: ‘AkiraBot’ Spammed 80,000 Web sites With AI-Generated Messages

Associated: Second OttoKit Vulnerability Exploited to Hack WordPress Websites

Associated: Vulnerability in OttoKit WordPress Plugin Exploited within the Wild

Associated: Risk Actors Deploy WordPress Malware in ‘mu-plugins’ Listing

Security Week News Tags:Exploited, Hack, Motors, Theme, Vulnerability, Websites, WordPress

Post navigation

Previous Post: FreeType Zero-Day Found by Meta Exploited in Paragon Spyware Attacks
Next Post: Godfather Android Trojan Creates Sandbox on Infected Devices

Related Posts

FireCompass Raises $20 Million for Offensive Security Platform Security Week News
Akira Ransomware Attacks Fuel Uptick in Exploitation of SonicWall Flaw Security Week News
CISA Confirms Exploitation of Latest Oracle EBS Vulnerability  Security Week News
Hawaiian Airlines Hacked as Aviation Sector Warned of Scattered Spider Attacks Security Week News
Aflac Finds Suspicious Activity on US Network That May Impact Social Security Numbers, Other Data Security Week News
Virtual Event Preview: Cloud & Data Security Summit – Tackling Exposed Attack Surfaces in the Cloud Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Ransomware Attack on European Organizations Surge as Hackers Leveraging AI-Tools for Attacks
  • Windows Cloud Files Mini Filter Driver Vulnerability Exploited to Escalate Privileges
  • October Sees Rise in Phishing and Ransomware Attacks, Including TyKit and Google Careers Scams
  • AI Engine WordPress Plugin Exposes 100,000 WordPress Sites to Privilege Escalation Attacks
  • 7 New Vulnerabilities in GPT-4o and GPT-5 Enables 0-Click Attacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Ransomware Attack on European Organizations Surge as Hackers Leveraging AI-Tools for Attacks
  • Windows Cloud Files Mini Filter Driver Vulnerability Exploited to Escalate Privileges
  • October Sees Rise in Phishing and Ransomware Attacks, Including TyKit and Google Careers Scams
  • AI Engine WordPress Plugin Exposes 100,000 WordPress Sites to Privilege Escalation Attacks
  • 7 New Vulnerabilities in GPT-4o and GPT-5 Enables 0-Click Attacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News