Skip to content
October 5, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
  • Home
  • News
  • Vulnerability Report
  • Urgent WordPress Alert: Motors Theme Flaw (CVE-2025-4322) Actively Exploited for Site Takeover
  • Vulnerability Report

Urgent WordPress Alert: Motors Theme Flaw (CVE-2025-4322) Actively Exploited for Site Takeover

Do Son June 20, 2025 3 minutes read
0
PAN-OS Root RCE CL-STA-1132 Exploitation Tianxin RCE CVE-2021-4473 React Native Supply Chain Attack AstrOOnauta Malware Gladinet Zero-Day, LFI RCE Chain WordPress Theme, Account Takeover CVE-2024-50623 - European Space Agency cyberattack
Add Daily CyberSecurity as a preferred source on Google

Last month, a critical vulnerability was reported to Wordfence that now threatens more than 22,000 WordPress websites using the popular Motors automotive dealership theme. Tracked as CVE-2025-4322 and rated CVSS 9.8, the vulnerability enables unauthenticated attackers to reset any user’s password, including administrators, resulting in full site takeover.

Running Infra, AppSec, and SOC teams? Tag WordPress alerts by team automatically.

Try Team free for 14 days →

“This vulnerability makes it possible for an unauthenticated attacker to change the password of any user, including an administrator, which allows them to take over the account and the website,” Wordfence warned in its blog post.

Following the public disclosure on May 19, threat actors began targeting vulnerable sites almost immediately, with mass exploitation observed beginning on June 7th, 2025. Since then, the Wordfence Firewall has blocked over 23,100 exploit attempts, confirming the vulnerability is under active attack.

The flaw lies in how the Motors theme handles the “Login Register” widget, which includes a password reset function. An attacker only needs to discover the page containing this widget and then manipulate the hash_check parameter to exploit the password reset mechanism.

Specifically, malformed or invalid UTF-8 characters—such as %80, %C0, or %25C0—are passed into the hash_check parameter. These characters are stripped during processing, causing the hash comparison to erroneously succeed and allowing the attacker to set a new password.

“The hash_check parameter must be a sequence of invalid utf8 character(s), which get stripped and cause the hash comparison to succeed,” Wordfence explains.

Attackers are attempting password resets across a wide range of common URL paths such as /reset-password, /account, or /signin. Below are sample attack payloads:

POST /index.php/login-register/?user_id=3&hash_check=%80
POST /account/?user_id=1&hash_check=%25C0
POST /reset-password?user_id=1&hash_check=%C0

These requests include the new password in the POST body under the parameter stm_new_password.

Wordfence identified the most active malicious IPs attempting to exploit CVE-2025-4322:

  • 198.2.233.90 – Over 4,700 blocked requests
  • 192.210.243.217 – Over 3,600
  • 123.253.111.178 – Over 3,200
  • 217.142.21.233, 8.217.154.123, and others have also been flagged

“Most of the requests we blocked would likely have led to site compromises if they did not have Wordfence installed,” the report warns.

If you’re using the Motors theme and:

  • Admin credentials no longer work
  • New unauthorized admin accounts have appeared
  • Access logs show suspicious hash_check parameters (starting with % and short in length)

…it’s possible your site has been compromised.

Look for these access log patterns:

?user_id=1&hash_check=%80
?user_id=1&hash_check=%C0

If your site uses the Motors WordPress theme, take the following steps immediately:

  • Update to version 5.6.68 or later, the only currently patched version
  • Review your admin users list for suspicious accounts
  • Monitor your access logs for hash_check anomalies
  • Enable and configure a firewall like Wordfence, which is actively blocking this exploit

Related Posts:

  • High Risk (CVSS 9.8): Motors Theme Flaw Exposes 22,000+ WordPress Sites to Full Takeover
  • Kawasaki Europe Navigates Ransomware Incident, Recovery in Progress
  • WordPress Malware Alert: Fake Anti-Malware Plugin Grants Admin Access and Executes Remote Code
  • New WordPress Malware Masquerades as Legit Plugin with Data Exfiltration and RCE Capabilities

Related coverage

  • Public PoC Code Exposes CVSS 9.8 Control Web Panel SQL Injection CVE-2026-57517
  • MongoDB Patches 24 Server Vulnerabilities, One Critical
  • Adobe AEM Forms Patch: Critical Flaws (CVE-2025-54253, CVSS 10.0) Allow RCE & Arbitrary File Read, Public PoCs Available
  • CVE-2026-18051 (CVSS 10): Unauthenticated Arbitrary File Write Hits 900k W3 Total Cache Sites
  • NVIDIA Critical AI Patch: Isaac Lab and NeMo Framework Flaws Risk Full Code Execution
  • CVE-2026-82329 Exploited: JFrog Artifactory Admin Takeover
Track all actively exploited CVEs →

Support Our Threat Intelligence

Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!

Buy Me a Coffee Logo Buy Me a Coffee
Select your plan
Free Pro Team

Hover over a plan to see its benefits.

Get Zero-Hour Vulnerability Alerts

Critical CVEs, CVSS scores, and PoC updates — straight to your inbox every week.

We respect your inbox. Unsubscribe anytime.

SHARE
Share on FacebookShare on XShare on LinkedInShare on TelegramShare on BlueskyShare on Mastodon
Written by
@DdoS · Security Researcher

Do Son

Do Son is the Founder and Editor of SecurityOnline.info. Working in cybersecurity since 2013, he reports on vulnerabilities, malware, and emerging threats, providing timely analysis to help organizations and individuals stay ahead of evolving risks.

Tags: Account Takeover CVE-2025-4322 cybersecurity Motors theme Patch Now privilege escalation Vulnerability Web Security Wordfence wordpress

Leave a Reply Cancel reply

You must be logged in to post a comment.

Search

Translation

CVE ALERTS
📈

EPSS Spike Alerts
Catch risk spikes before they make headlines.

🎯

Custom EPSS/CVSS
Set score thresholds to effectively filter noise.

🛡️

Exploit Intel
Real-world exploit signals beyond the KEV catalog.

🐙

GitHub Issues
Auto-create alert tickets without duplication.

📬

Weekly Digest
Clean summaries, eliminating email spam.

🏷️

Watchlist Groups
Tag vulnerabilities by team (Infra/AppSec/SOC).

🔀

Smart Routing
Route chat channels based on severity levels.

🚨

RBP Tracker
Early warning detection and tracking system.

Subscribe – $7/mo or try free for 14 days →

🚨 Active Exploits in the Wild

  • CVE-2026-88779CVSS 8.7
    Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS,...
    Admin intelCISA KEV📅 Added to KEV: Oct 4, 2026📅 Updated: Oct 4, 2026
  • CVE-2026-102490CVSS 8.5
    All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.
    Admin intelCISA KEV📅 Added to KEV: Oct 2, 2026📅 Updated: Oct 2, 2026
  • CVE-2026-102489CVSS 8.7
    Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as...
    Admin intelCISA KEV📅 Added to KEV: Oct 2, 2026📅 Updated: Oct 2, 2026
  • CVE-2026-100382CVSS 10.0
    Improper Neutralization of Special Elements used in an OS Command (\'OS Command Injection\') vulnerability in Wikimedia Foundation Mediawiki...
    Admin intel📅 Updated: Oct 1, 2026
  • CVE-2026-104286CVSS 9.8
    An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through...
    CISA KEV📅 Added to KEV: Oct 1, 2026
  • CVE-2026-76504CVSS 9.8
    A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote...
    Admin intelCISA KEV📅 Added to KEV: Sep 30, 2026📅 Updated: Sep 30, 2026
  • CVE-2026-86950CVSS 8.8
    An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and...
    Admin intelCISA KEV📅 Added to KEV: Sep 29, 2026📅 Updated: Sep 29, 2026
  • CVE-2026-88772
    Memory overflow vulnerability leading to remote code execution or denial of service.
    Admin intelCISA KEV📅 Added to KEV: Sep 27, 2026📅 Updated: Sep 27, 2026
Powered by CVE Watchtower

Critical Vulnerabilities

  • CVE-2026-100781CVSS 9.6
    Sandbox escape due to incorrect boundary conditions in the Graphics: WebRender component. This vulnerability was fixed in Firefox...
    📅 Updated: Oct 5, 2026
  • CVE-2026-105293CVSS 9.2
    Legcord 1.1.0 through 1.3.0 contains a path traversal vulnerability in theme IPC handlers that allows script in the...
    📅 Updated: Oct 5, 2026
  • CVE-2026-100551CVSS 9.0
    OpenClaw for iOS versions >= 2026.7.1 and < 2026.8.11 do not enforce saved Gateway TLS pins in the...
    📅 Updated: Oct 5, 2026
  • CVE-2026-105218CVSS 9.1
    gopay before 1.5.119 disables TLS certificate verification in defaultClient() in pkg/xhttp/client.go, allowing man-in-the-middle attackers to impersonate payment provider...
    📅 Updated: Oct 5, 2026
  • CVE-2026-82042CVSS 9.3
    UTMStack before 11.2.16 contains an authentication bypass vulnerability that allows remote attackers to gain full administrative API access...
    📅 Updated: Oct 5, 2026
  • CVE-2026-79820CVSS 9.0
    A remote user validation failure vulnerability exists in HPE Integrated Lights-Out (iLO) 7 firmware.
    📅 Updated: Oct 5, 2026
  • CVE-2026-105223CVSS 9.1
    maclof kubernetes-client 0.17.0 before 0.32.0 disables TLS certificate verification in parseKubeconfig() and parseKubeconfigFile() when a kubeconfig lacks certificate-authority-data,...
    📅 Updated: Oct 5, 2026
  • CVE-2025-6544CVSS 9.8
    A deserialization vulnerability exists in h2oai/h2o-3 versions
    📅 Updated: Oct 5, 2026
Powered by CVE Watchtower

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.