A critical vulnerability in the Motors theme for WordPress was exploited in mass attacks, risking site compromise for over 22,000 websites. Immediate updates are recommended to mitigate privilege escalation and account takeover risks. #CVE-2025-4322 #MotorsTheme #WordPressSecurity
Keypoints
- The vulnerability CVE-2025-4322 allows privilege escalation via account takeover on affected sites.
- The flaw exists in the themeβs password recovery function, enabling unauthorized password changes.
- Over 22,000 websites use the Motors theme, with more than 23,000 exploit attempts blocked since disclosure.
- The security issue was patched in version 5.6.68 of the Motors theme on May 14.
- Successful exploitation can lead to full site compromise, including malicious file uploads and content modification.
Read More: https://www.securityweek.com/motors-theme-vulnerability-exploited-to-hack-wordpress-websites/