ZeroHour

CVE-2022-3989

PoC
CVSS 3.1
8.8 high
EPSS
1%p62
Published
()
Modified
Description

The Motors WordPress plugin before 1.4.4 does not properly validate uploaded files for dangerous file types (such as .php) in an AJAX action, allowing an attacker to sign up on a victim's WordPress instance, upload a malicious PHP file and attempt to launch a brute-force attack to discover the uploaded payload.

Vendors
stylemixthemes
Products
motors - car dealer\, classifieds \& listing
Ecosystems
WordPress
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.