CVE-2022-3989
PoC —CVSS 3.1
8.8 high
EPSS
1%p62
Published
()
Modified
Description
The Motors WordPress plugin before 1.4.4 does not properly validate uploaded files for dangerous file types (such as .php) in an AJAX action, allowing an attacker to sign up on a victim's WordPress instance, upload a malicious PHP file and attempt to launch a brute-force attack to discover the uploaded payload.
- Vendors
- stylemixthemes
- Products
- motors - car dealer\, classifieds \& listing
- Ecosystems
- WordPress
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.