Skip to content
July 29, 2026
  • Linkedin
  • Twitter
  • Facebook
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
  • Cyber Criminals
  • Data Leak
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
  • Home
  • News
  • Vulnerability Report
  • Urgent WordPress Alert: Motors Theme Flaw (CVE-2025-4322) Actively Exploited for Site Takeover
  • Vulnerability Report

Urgent WordPress Alert: Motors Theme Flaw (CVE-2025-4322) Actively Exploited for Site Takeover

Do Son June 20, 2025 3 minutes read
0
PAN-OS Root RCE CL-STA-1132 Exploitation Tianxin RCE CVE-2021-4473 React Native Supply Chain Attack AstrOOnauta Malware Gladinet Zero-Day, LFI RCE Chain WordPress Theme, Account Takeover CVE-2024-50623 - European Space Agency cyberattack
Add Daily CyberSecurity as a preferred source on Google

Last month, a critical vulnerability was reported to Wordfence that now threatens more than 22,000 WordPress websites using the popular Motors automotive dealership theme. Tracked as CVE-2025-4322 and rated CVSS 9.8, the vulnerability enables unauthenticated attackers to reset any user’s password, including administrators, resulting in full site takeover.

“This vulnerability makes it possible for an unauthenticated attacker to change the password of any user, including an administrator, which allows them to take over the account and the website,” Wordfence warned in its blog post.

Following the public disclosure on May 19, threat actors began targeting vulnerable sites almost immediately, with mass exploitation observed beginning on June 7th, 2025. Since then, the Wordfence Firewall has blocked over 23,100 exploit attempts, confirming the vulnerability is under active attack.

The flaw lies in how the Motors theme handles the “Login Register” widget, which includes a password reset function. An attacker only needs to discover the page containing this widget and then manipulate the hash_check parameter to exploit the password reset mechanism.

Specifically, malformed or invalid UTF-8 characters—such as %80, %C0, or %25C0—are passed into the hash_check parameter. These characters are stripped during processing, causing the hash comparison to erroneously succeed and allowing the attacker to set a new password.

“The hash_check parameter must be a sequence of invalid utf8 character(s), which get stripped and cause the hash comparison to succeed,” Wordfence explains.

Attackers are attempting password resets across a wide range of common URL paths such as /reset-password, /account, or /signin. Below are sample attack payloads:

POST /index.php/login-register/?user_id=3&hash_check=%80
POST /account/?user_id=1&hash_check=%25C0
POST /reset-password?user_id=1&hash_check=%C0

These requests include the new password in the POST body under the parameter stm_new_password.

Wordfence identified the most active malicious IPs attempting to exploit CVE-2025-4322:

  • 198.2.233.90 – Over 4,700 blocked requests
  • 192.210.243.217 – Over 3,600
  • 123.253.111.178 – Over 3,200
  • 217.142.21.233, 8.217.154.123, and others have also been flagged

“Most of the requests we blocked would likely have led to site compromises if they did not have Wordfence installed,” the report warns.

If you’re using the Motors theme and:

  • Admin credentials no longer work
  • New unauthorized admin accounts have appeared
  • Access logs show suspicious hash_check parameters (starting with % and short in length)

…it’s possible your site has been compromised.

Look for these access log patterns:

?user_id=1&hash_check=%80
?user_id=1&hash_check=%C0

If your site uses the Motors WordPress theme, take the following steps immediately:

  • Update to version 5.6.68 or later, the only currently patched version
  • Review your admin users list for suspicious accounts
  • Monitor your access logs for hash_check anomalies
  • Enable and configure a firewall like Wordfence, which is actively blocking this exploit

Related Posts:

  • High Risk (CVSS 9.8): Motors Theme Flaw Exposes 22,000+ WordPress Sites to Full Takeover
  • Kawasaki Europe Navigates Ransomware Incident, Recovery in Progress
  • WordPress Malware Alert: Fake Anti-Malware Plugin Grants Admin Access and Executes Remote Code
  • New WordPress Malware Masquerades as Legit Plugin with Data Exfiltration and RCE Capabilities

Get Zero-Hour Vulnerability Alerts

Critical CVEs, CVSS scores, and PoC updates — straight to your inbox every week.


We respect your inbox. Unsubscribe anytime.

Related coverage

  • Multiple Security Flaws Fixed in Major Framework Release
  • High-Severity Rockwell Flaws Risk Industrial SQLi Data Tampering and Safety Device DoS Requiring Manual Fix
  • High-Severity Flaw Exposes LiteSpeed Web Servers to OS Command Injection
  • Below the EDR: How Unsecured IP-KVM Switches Grant Total System Takeover
  • Critical Gitea Security Flaws Expose Servers to Takeover
Track all actively exploited CVEs →

Support Our Threat Intelligence

If you find our CVE report and cybersecurity news helpful, consider supporting our work.

Buy Me a Coffee Logo Buy Me a Coffee PayPal
Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Share this article:

Facebook Post LinkedIn Telegram
Written by
@DdoS · Security Researcher

Do Son

Do Son is the Founder and Editor of SecurityOnline.info. Working in cybersecurity since 2013, he reports on vulnerabilities, malware, and emerging threats, providing timely analysis to help organizations and individuals stay ahead of evolving risks.

Tags: Account Takeover CVE-2025-4322 cybersecurity Motors theme Patch Now privilege escalation Vulnerability Web Security Wordfence wordpress

Leave a Reply Cancel reply

You must be logged in to post a comment.

Search

Translation

CVE WATCHTOWER
🚨

Receive alerts for vulnerabilities being exploited in the wild.

⚡

Get notified instantly when a Proof of Concept (PoC) exploit is published.

🔍

Access critical info on vulnerabilities even when marked as "RESERVED".

🧠

Insights powered by decades of expertise and global intelligence sources.

🎯

Customize alerts with up to 10 keywords for your specific tech stack.

📊

Export the raw CVE database for SIEM integration and reporting.

Upgrade Package

🚨 Active Exploits in the Wild

  • CVE-2026-18072CVSS 9.8
    The Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … plugin for WordPress is vulnerable to...
    Admin intel📅 Updated: Jul 29, 2026
  • CVE-2026-16812CVSS 10.0
    VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access...
    Admin intelCISA KEV📅 Added to KEV: Jul 27, 2026📅 Updated: Jul 27, 2026
  • CVE-2025-68686CVSS 5.9
    An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1,...
    CISA KEV📅 Added to KEV: Jul 27, 2026
  • CVE-2026-16723CVSS 9.0
    A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson\'s stock...
    Admin intel📅 Updated: Jul 25, 2026
  • CVE-2026-16232CVSS 9.1
    An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain...
    CISA KEV📅 Added to KEV: Jul 22, 2026
  • CVE-2026-50522CVSS 9.8
    Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
    Admin intelCISA KEV📅 Added to KEV: Jul 22, 2026📅 Updated: Jul 21, 2026
  • CVE-2026-63030CVSS 9.8
    WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion...
    Admin intelCISA KEV📅 Added to KEV: Jul 21, 2026📅 Updated: Jul 21, 2026
  • CVE-2026-60137CVSS 5.9
    WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter...
    Admin intelCISA KEV📅 Added to KEV: Jul 21, 2026📅 Updated: Jul 21, 2026
Powered by CVE Watchtower

🔴 Live Critical Threats

  • CVE-2026-14900CVSS 9.8
    The Cost Calculator Builder PRO plugin for WordPress is vulnerable to Remote...
  • CVE-2026-14488CVSS 9.1
    The Meta Box AIO plugin for WordPress is vulnerable to Missing Authorization...
  • CVE-2025-10656CVSS 9.8
    The Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light plugin...
  • CVE-2026-58162CVSS 10.0
    The Apache Traffic Server certifier plugin generates certificates based on attacker-controlled client...
  • CVE-2026-58155CVSS 9.3
    Apache Traffic Server truncates over-long header names, allowing header aliasing, request smuggling,...
  • CVE-2026-58150CVSS 10.0
    Apache Traffic Server does not reject Transfer-Encoding in HTTP/2 requests, allowing downgrade...
  • CVE-2026-57834CVSS 10.0
    Apache Traffic Server allows request smuggling if chunked messages are malformed. This...
  • CVE-2026-33267CVSS 10.0
    Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache...
  • CVE-2026-41920CVSS 9.3
    Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache...
  • CVE-2026-63234CVSS 9.9
    A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an...
Powered by CVE WATCHTOWER

Our Websites
  • Penetration Testing Tools
  • The Daily Information Technology
  • Top Exploited CVEs
  • Daily CyberSecurity

    • About SecurityOnline.info
    • Advertise with us
    • Announcement
    • Contact
    • Contributor Register
    • Login
    • Disclaimer
    • DCMA
    • Privacy Policy
    • About SecurityOnline.info
    • Advertise on SecurityOnline.info
    • Contact Us

    When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

    • CVE Watchtower
    • CVE Statistics by Vendor 2026
    • Q2 2026 Report
    • Top Exploited CVEs
    • Linkedin
    • Twitter
    • Facebook
    • Youtube
    © 2017 - 2026 Daily CyberSecurity. All Rights Reserved.